CVE-2021-3326: High severity ibm security verify access oidc provider vulnerability
GNU C Library (aka glibc or libc6) is vulnerable to a denial of service, caused by an assertion failure when processing invalid input sequences in the ISO-2022-JP-3 encoding in the iconv function. By sending specially-crafted input, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
The iconv function in the GNU C Library (aka glibc or libc6) 2.32 and earlier, when processing invalid input sequences in the ISO-2022-JP-3 encoding, fails an assertion in the code path and aborts the program, potentially resulting in a denial of service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3326?
CVE-2021-3326 is a vulnerability in the GNU C Library (glibc) that allows for a denial of service attack.
How severe is CVE-2021-3326?
CVE-2021-3326 has a severity score of 7.5, which is considered high.
Which software versions are affected by CVE-2021-3326?
IBM Security Verify Access 10.0.0, GNU glibc up to version 2.32.0, and NetApp E-Series SANtricity OS Controller versions between 11.0 and 11.60.3 are affected by CVE-2021-3326.
How can I fix CVE-2021-3326?
To fix CVE-2021-3326, you should update to a version of the affected software that includes a patch for the vulnerability.
Where can I find more information about CVE-2021-3326?
You can find more information about CVE-2021-3326 in the references provided: [1], [2], [3].