The glibc iconv overflow: a character-set conversion bug that turned php file reads into code execution
On its own, a buffer overflow of a few bytes in a character-set converter. In practice, the missing step that let researchers turn an ordinary PHP file-disclosure bug into remote code execution.
A fixed package version is available on 6 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.
What it actually is
The iconv() function overflows its output buffer by up to four bytes when converting to the ISO-2022-CN-EXT character set. Any program that lets untrusted input choose a target character set can reach it.
What an attacker gets: A small, precisely controlled memory overwrite. Its importance is as a second stage: chained with a file-read primitive in an application, it has been demonstrated to produce remote code execution.
When it applies to you, and when it does not
An old package version and a real exposure are different things. These are the conditions this one needs.
- It needs an application that passes attacker-influenced data to iconv with an attacker-influenced target charset. PHP does this through several ordinary stream filters, which is why PHP applications were the demonstrated route.
- The ISO-2022-CN-EXT converter has to be present. It is part of the standard glibc locale data on every distribution below.
- Patch glibc and restart. A long-running PHP-FPM pool keeps the old library mapped until it does.
Check your own server
ldd --version | head -1 && iconv -l | grep -c ISO-2022-CN-EXTA count of 1 or more means the affected converter is available on this machine.
Fixed package version, per distribution
From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.
| Release | Source package | State | Fixed in |
|---|---|---|---|
| Ubuntu 22.04 LTS | glibc | Fixed | 2.35-0ubuntu3.7 |
| Ubuntu 24.04 LTS | glibc | Fixed | 2.39-0ubuntu8.1 |
| Debian 12 (bookworm) | glibc | Fixed | 2.36-9+deb12u6 |
| Debian 13 (trixie) | glibc | Fixed | 2.37-18 |
| Rocky Linux 9 | glibc | Fixed | 0:2.34-100.el9_4.2 |
| AlmaLinux 9 | glibc | Fixed | 2.34-100.el9_4.2 |
Install the fix with apt update && apt install --only-upgrade libc6 libc-bin on Debian and Ubuntu, or dnf update glibc glibc-common on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.
What SecAI has recorded about it
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
Recorded from nvd. Its weakness class is CWE-787, from NVD.
- http://www.openwall.com/lists/oss-security/2024/04/17/9
- http://www.openwall.com/lists/oss-security/2024/04/18/4
- http://www.openwall.com/lists/oss-security/2024/04/24/2
- http://www.openwall.com/lists/oss-security/2024/05/27/1
- http://www.openwall.com/lists/oss-security/2024/05/27/2
- http://www.openwall.com/lists/oss-security/2024/05/27/3
Read next
Check whether this vulnerability affects your Linux server
One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2024-2961 included. It changes nothing.