GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 23 Jun 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Out‑of‑Bounds Read in libidn’s ToUnicode API |
Tue, 23 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 23 Jun 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2. | |
| First Time appeared |
Gnu
Gnu libidn |
|
| Weaknesses | CWE-1284 | |
| CPEs | cpe:2.3:a:gnu:libidn:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gnu
Gnu libidn |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-23T17:40:14.173Z
Reserved: 2026-06-23T16:40:22.560Z
Link: CVE-2026-57053
Updated: 2026-06-23T17:40:10.988Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-23T19:30:04Z
Weaknesses