CVE-2016-10228: GNU Glibc

Medium severity, CVSS 5.9. EPSS: 4% chance of exploitation in the next 30 days.

The iconv program in the GNU C Library (aka glibc or libc6) 2.31 and earlier, when invoked with multiple suffixes in the destination encoding (TRANSLATE or IGNORE) along with the -c option, enters an infinite loop when processing invalid multi-byte input sequences, leading to a denial of service.

Affected products

  • GNU Glibc: up to and including 2.25

Published 2017-03-02. Last modified 2026-06-17.