CVE-2024-2961

high

Description

The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.

References

https://github.com/qinglove777/CVE-2024-2961-XXE-Exploit

https://github.com/HORKimhab/CVE-2022-31626-CVE-2024-2961-CVE-2019-6977

https://github.com/roundcube-utils/cnext-exploits

https://github.com/darkrapid8/cnext-exploits

https://github.com/hhhell/CVE-Vulnerability-Reproduction

https://github.com/shane-snyder/ocp-cve-fixes

https://github.com/whyuhurtz/wongpress

https://github.com/cbrkrtek/ai-devsecops-auto-remediation

https://github.com/rcribelar-nucleus/demo-php-cve-2024-2961

https://github.com/Clarissss/osTicketFileReadIntoRCE

https://github.com/horizon3ai/CVE-2026-22200

https://github.com/owl-nosleep/CVEs-Analysis

https://github.com/muffinthecoder/CNEXT_BufferOverflow_CVE2024-2961

https://github.com/scriptSails/glibcs

https://github.com/regantemudo/PHP-file-read-to-RCE-CVE-2024-2961-

https://github.com/mesudmammad1/CVE-2023-26326_Buddyform_exploit

https://github.com/omarelshopky/exploit_cve-2023-26326_using_cve-2024-2961

https://github.com/4wayhandshake/CVE-2024-2961

https://github.com/etx-Arn/CVE-2024-34102-RCE-PoC

https://github.com/etx-Arn/CVE-2024-34102-RCE

https://github.com/jakabakos/CVE-2024-34102-CosmicSting-XXE-in-Adobe-Commerce-and-Magento

https://github.com/absolutedesignltd/iconvfix

https://github.com/ambionics/cnext-exploits

https://github.com/rvizx/CVE-2024-2961

https://lists.fedoraproject.org/archives/list/[email protected]/message/YAMJQI3Y6BHWV3CUTYBXOZONCUJNOB2Z/

https://lists.fedoraproject.org/archives/list/[email protected]/message/P3I4KYS6EU6S7QZ47WFNTPVAHFIUQNEL/

https://lists.fedoraproject.org/archives/list/[email protected]/message/BTJFBGHDYG5PEIFD5WSSSKSFZ2AZWC5N/

https://cert-portal.siemens.com/productcert/html/ssa-082556.html

Details

Source: Mitre, NVD

Published: 2024-04-17

Updated: 2026-05-12

Named Vulnerability: CNEXT

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.3

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

Severity: High

EPSS

EPSS: 0.8833