CVE-2024-2961: Debian Linux
High severity, CVSS 7.3. EPSS: 88.3% chance of exploitation in the next 30 days.
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
Affected products
- Debian Debian Linux: version 10.0 only
- GNU Glibc: from 2.1.93, before 2.40 (fixed in 2.40)
- Netapp Active Iq Unified Manager: affected versions not specified
- Netapp Hci Compute Node: affected versions not specified
- Netapp Hci h300s Firmware: affected versions not specified
- Netapp Hci h410c Firmware: affected versions not specified
- Netapp Hci h410s Firmware: affected versions not specified
- Netapp Hci h500s Firmware: affected versions not specified
- Netapp Hci h610c Firmware: affected versions not specified
- Netapp Hci h610s Firmware: affected versions not specified
- Netapp Hci h615c Firmware: affected versions not specified
- Netapp Hci h700s Firmware: affected versions not specified
- Netapp Ontap Select Deploy Administration Utility: affected versions not specified
Published 2024-04-17. Last modified 2026-06-17.