CVE-2024-2961: Debian Linux

High severity, CVSS 7.3. EPSS: 88.3% chance of exploitation in the next 30 days.

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

Affected products

  • Debian Debian Linux: version 10.0 only
  • GNU Glibc: from 2.1.93, before 2.40 (fixed in 2.40)
  • Netapp Active Iq Unified Manager: affected versions not specified
  • Netapp Hci Compute Node: affected versions not specified
  • Netapp Hci h300s Firmware: affected versions not specified
  • Netapp Hci h410c Firmware: affected versions not specified
  • Netapp Hci h410s Firmware: affected versions not specified
  • Netapp Hci h500s Firmware: affected versions not specified
  • Netapp Hci h610c Firmware: affected versions not specified
  • Netapp Hci h610s Firmware: affected versions not specified
  • Netapp Hci h615c Firmware: affected versions not specified
  • Netapp Hci h700s Firmware: affected versions not specified
  • Netapp Ontap Select Deploy Administration Utility: affected versions not specified

Published 2024-04-17. Last modified 2026-06-17.