CVE-2026-6042: Musl Libc

Low severity, CVSS 3.3. EPSS: 0.2% chance of exploitation in the next 30 days.

A security flaw has been discovered in musl libc up to 1.2.6. Affected is the function iconv of the file src/locale/iconv.c of the component GB18030 4-byte Decoder. Performing a manipulation results in inefficient algorithmic complexity. The attack must be initiated from a local position. To fix this issue, it is recommended to deploy a patch.

Affected products

  • Musl Libc: version 1.2.0 only; version 1.2.1 only; version 1.2.2 only; version 1.2.3 only; version 1.2.4 only; version 1.2.5 only; …

Published 2026-04-10. Last modified 2026-06-17.