{"id":"CVE-2021-43396","details":"In iconvdata/iso-2022-jp-3.c in the GNU C Library (aka glibc) 2.34, remote attackers can force iconv() to emit a spurious '\\0' character via crafted ISO-2022-JP-3 data that is accompanied by an internal state reset. This may affect data integrity in certain iconv() use cases. NOTE: the vendor states \"the bug cannot be invoked through user input and requires iconv to be invoked with a NULL inbuf, which ought to require a separate application bug to do so unintentionally. Hence there's no security impact to the bug.","modified":"2026-08-30T11:46:03.846100394Z","published":"2021-11-04T20:15:09.223Z","database_specific":{"unresolved_ranges":[{"vendor_product":"oracle:communications_cloud_native_core_binding_support_function","cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"22.1.3"},{"last_affected":"22.1.3"}],"source":"CPE_STRING"},{"vendor_product":"oracle:communications_cloud_native_core_network_function_cloud_native_environment","cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"22.1.0"},{"last_affected":"22.1.0"}],"source":"CPE_STRING"},{"vendor_product":"oracle:communications_cloud_native_core_network_repository_function","cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.1.2:*:*:*:*:*:*:*","cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"22.1.2"},{"last_affected":"22.1.2"},{"introduced":"22.2.0"},{"last_affected":"22.2.0"}],"source":"CPE_STRING"},{"extracted_events":[{"introduced":"22.1.1"},{"last_affected":"22.1.1"}],"source":"CPE_STRING","vendor_product":"oracle:communications_cloud_native_core_security_edge_protection_proxy","cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:22.1.1:*:*:*:*:*:*:*"]},{"cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:22.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"22.2.0"},{"last_affected":"22.2.0"}],"source":"CPE_STRING","vendor_product":"oracle:communications_cloud_native_core_unified_data_repository"},{"source":"CPE_STRING","vendor_product":"oracle:enterprise_operations_monitor","cpes":["cpe:2.3:a:oracle:enterprise_operations_monitor:4.3:*:*:*:*:*:*:*","cpe:2.3:a:oracle:enterprise_operations_monitor:4.4:*:*:*:*:*:*:*","cpe:2.3:a:oracle:enterprise_operations_monitor:5.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"4.3"},{"last_affected":"4.3"},{"introduced":"4.4"},{"last_affected":"4.4"},{"introduced":"5.0"},{"last_affected":"5.0"}]}]},"references":[{"type":"WEB","url":"https://sourceware.org/git/?p=glibc.git%3Ba=commit%3Bh=ff012870b2c02a62598c04daa1e54632e020fd7d"},{"type":"REPORT","url":"https://sourceware.org/bugzilla/show_bug.cgi?id=28524"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"EVIDENCE","url":"https://blog.tuxcare.com/vulnerability/vulnerability-in-iconv-identified-by-tuxcare-team-cve-2021-43396"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bminor/glibc","events":[{"introduced":"ae37d06c7d127817ba43850f0f898b793d42aea7"},{"last_affected":"ae37d06c7d127817ba43850f0f898b793d42aea7"}],"database_specific":{"source":"CPE_STRING","cpe":"cpe:2.3:a:gnu:glibc:2.34:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.34"},{"last_affected":"2.34"}]}}],"versions":["2.34","glibc-2.34"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-43396.json"}},{"ranges":[{"type":"GIT","repo":"https://sourceware.org/git/glibc.git","events":[{"introduced":"ae37d06c7d127817ba43850f0f898b793d42aea7"},{"last_affected":"ae37d06c7d127817ba43850f0f898b793d42aea7"}],"database_specific":{"extracted_events":[{"introduced":"2.34"},{"last_affected":"2.34"}],"source":"CPE_STRING","cpe":"cpe:2.3:a:gnu:glibc:2.34:*:*:*:*:*:*:*"}}],"versions":["2.34","glibc-2.34"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-43396.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}