CVE-2020-27618: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.9% chance of exploitation in the next 30 days.

The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid multi-byte input sequences in IBM1364, IBM1371, IBM1388, IBM1390, and IBM1399 encodings, fails to advance the input state, which could lead to an infinite loop in applications, resulting in a denial of service, a different vulnerability from CVE-2016-10228.

Affected products

  • Debian Debian Linux: version 10.0 only
  • GNU Glibc: up to and including 2.32
  • Netapp 500f Firmware: affected versions not specified
  • Netapp a250 Firmware: affected versions not specified
  • Netapp h300e Firmware: affected versions not specified
  • Netapp h300s Firmware: affected versions not specified
  • Netapp h410c Firmware: affected versions not specified
  • Netapp h410s Firmware: affected versions not specified
  • Netapp h500e Firmware: affected versions not specified
  • Netapp h500s Firmware: affected versions not specified
  • Netapp h700e Firmware: affected versions not specified
  • Netapp h700s Firmware: affected versions not specified
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified
  • Oracle Communications Cloud Native Core Service Communication Proxy: version 1.14.0 only

Published 2021-02-26. Last modified 2026-06-17.