CVE-2015-7547

high
Published 2016-02-18 ยท Modified 2026-05-06
CVSS v3
8.1
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
9.1

Description

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

Predictions

Exploit likelihood
88%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-39454 dos linux verified
Google Security Research ยท 2016-02-16

glibc - 'getaddrinfo' Stack Buffer Overflow (PoC)

Source code queued for fetch โ€” refresh in a moment.
EDB-40339 remote linux
SpeeDr00t ยท 2016-09-06

glibc - 'getaddrinfo' Remote Stack Buffer Overflow

Source code queued for fetch โ€” refresh in a moment.

OS impact

redhat Red Hat Affected 1 release
VersionStatusFixed in
7.0 Affected โ€”
suse SUSE Affected 3 releases
VersionStatusFixed in
13.2 Affected โ€”
12 Affected โ€”
11.0 Affected โ€”
ubuntu Ubuntu Affected 3 releases
VersionStatusFixed in
15.10 Affected โ€”
14.04 Affected โ€”
12.04 Affected โ€”
debian Debian Mixed 6 releases
VersionStatusFixed in
trixie Fixed 2.21-8
sid Fixed 2.21-8
forky Fixed 2.21-8
bullseye Fixed 2.21-8
bookworm Fixed 2.21-8
8.0 Affected โ€”

Application impact

VendorProductVersionsFixed
hp hphelion_openstack1.1.1
hp hphelion_openstack2.0.0
hp hphelion_openstack2.1.0
hp hpserver_migration_pack7.5
sophosunified_threat_management_software9.319
sophosunified_threat_management_software9.355
suse suselinux_enterprise_debuginfo11.0
oracle oracleexalogic_infrastructure1.0
oracle oracleexalogic_infrastructure2.0
f5big-ip_access_policy_manager12.0.0
f5big-ip_advanced_firewall_manager12.0.0
f5big-ip_analytics12.0.0
f5big-ip_application_acceleration_manager12.0.0
f5big-ip_application_security_manager12.0.0
f5big-ip_domain_name_system12.0.0
f5big-ip_link_controller12.0.0
f5big-ip_local_traffic_manager12.0.0
f5big-ip_policy_enforcement_manager12.0.0
gnuglibc2.9
gnuglibc2.10
gnuglibc2.10.1
gnuglibc2.11
gnuglibc2.11.1
gnuglibc2.11.2
gnuglibc2.11.3
gnuglibc2.12
gnuglibc2.12.1
gnuglibc2.12.2
gnuglibc2.13
gnuglibc2.14
gnuglibc2.14.1
gnuglibc2.15
gnuglibc2.16
gnuglibc2.17
gnuglibc2.18
gnuglibc2.19
gnuglibc2.20
gnuglibc2.21
gnuglibc2.22

References

CWEs

CWE-119

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.