* GNU Libidn Security Advisory: Read out of bounds in ToUnicode APIs

The Libidn ToUnicode API family (idna_to_unicode*) will read out of
bounds for some input strings.

Report with analysis, reproducer and a suggested solution:

https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html

** Severity and Vulnerable versions

Severity: Low

Affected are GNU Libidn since at least version 0.1.15 from 2003-06-07
up to and including version 1.43 released on 2025-03-21.

** Recommendation

- Upgrade to Libidn version 1.44 or later.

- Apply the patch to your older Libidn release.

** Patch

The solution was suggested in the initial report:

https://codeberg.org/libidn/libidn/commit/f57fab06afc1e328bbe197ad3d4a4e83c829593e

** Credits

Reported by DMSAN (Differential Memory Sanitizer) on 2026-05-19
including analysis, proof of concept and suggested fix.

GNU Libidn 1.44 including the fix was released on 2026-06-16.

This advisory was drafted by Simon Josefsson on 2026-06-16.

Attachment: signature.asc
Description: PGP signature

Reply via email to