Buffer Overflow Vulnerability in Iconv Encoding Modules by FreeBSD
CVE-2026-58081

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-58081?

The iconv encoding modules in FreeBSD, including HZ, UTF-7, VIQR, and ZW, are susceptible to buffer overflow vulnerabilities due to inadequate checks on the size of caller-supplied output buffers. Applications that utilize iconv(3) for converting untrusted input with these encodings may be at risk, potentially allowing attackers to execute arbitrary code or disrupt service.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nick Wellnhofer
Mark Johnston
.