CVE-2024-2961

The glibc iconv overflow: a character-set conversion bug that turned php file reads into code execution

On its own, a buffer overflow of a few bytes in a character-set converter. In practice, the missing step that let researchers turn an ordinary PHP file-disclosure bug into remote code execution.

GNU C LibraryNot in CISA’s Known Exploited catalogueEPSS 88.3% chance of an attempt in 30 daysCVSS 7.3CWE-787CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

A fixed package version is available on 6 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

The iconv() function overflows its output buffer by up to four bytes when converting to the ISO-2022-CN-EXT character set. Any program that lets untrusted input choose a target character set can reach it.

What an attacker gets: A small, precisely controlled memory overwrite. Its importance is as a second stage: chained with a file-read primitive in an application, it has been demonstrated to produce remote code execution.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • It needs an application that passes attacker-influenced data to iconv with an attacker-influenced target charset. PHP does this through several ordinary stream filters, which is why PHP applications were the demonstrated route.
  • The ISO-2022-CN-EXT converter has to be present. It is part of the standard glibc locale data on every distribution below.
  • Patch glibc and restart. A long-running PHP-FPM pool keeps the old library mapped until it does.

Check your own server

Read-only, changes nothing
ldd --version | head -1 && iconv -l | grep -c ISO-2022-CN-EXT

A count of 1 or more means the affected converter is available on this machine.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSglibcFixed2.35-0ubuntu3.7
Ubuntu 24.04 LTSglibcFixed2.39-0ubuntu8.1
Debian 12 (bookworm)glibcFixed2.36-9+deb12u6
Debian 13 (trixie)glibcFixed2.37-18
Rocky Linux 9glibcFixed0:2.34-100.el9_4.2
AlmaLinux 9glibcFixed2.34-100.el9_4.2

Install the fix with apt update && apt install --only-upgrade libc6 libc-bin on Debian and Ubuntu, or dnf update glibc glibc-common on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

Recorded from nvd. Its weakness class is CWE-787, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2024-2961 included. It changes nothing.