Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2015-7547

83
FAUCET Score

CVE-2015-7547 is a critical stack-based buffer overflow vulnerability in the glibc library's send_dg and send_vc functions, affecting numerous products from vendors like Canonical, Debian, Red Hat, and SUSE. With a CVSS score of 8.1 (HIGH), it allows remote attackers to cause denial of service or potentially execute arbitrary code via crafted DNS responses, requiring high attack complexity but no user interaction. While not listed on the KEV catalog, exploit code is publicly available on ExploitDB, and it has garnered significant community discussion and media coverage, indicating a high level of awareness and potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
12.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
15.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:15.10:*:*:*:*:*:*:*
1.1.1CPE matchmatch criteria
cpe:2.3:a:hp:helion_openstack:1.1.1:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.1HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
89.56%
Probability of exploitation in next 30 days
EPSS Percentile
99.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
ExploitDB: EDB-40339 · Sep 6, 2016
This CVE's current EPSS score of 0.8956 is in the 100th percentile among its peer group of 8,914 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

latchsetpatch availablevia llm_extracted
View patch
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: glibc-0:2.17-106.el7_2.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Advanced Update SupportFixed in: glibc-0:2.12-1.132.el6_5.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.6 Extended Update SupportFixed in: glibc-0:2.12-1.149.el6_6.11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.1 Extended Update SupportFixed in: glibc-0:2.17-79.el7_1.4
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-6Fixed in: rhev-hypervisor6-0:6.7-20160104.2.el6ev
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-6Fixed in: rhev-hypervisor7-0:7.2-20160105.2.el6ev
View patch
redhatpatch availablevia redhat_api
Product: RHEV 3.X Hypervisor and Agents for RHEL-7Fixed in: rhev-hypervisor7-0:7.2-20160105.2.el7ev
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: glibc-0:2.12-1.166.el6_7.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.2 Advanced Update SupportFixed in: glibc-0:2.12-1.47.el6_2.17
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.4 Advanced Update SupportFixed in: glibc-0:2.12-1.107.el6_4.9
View patch
beegovendor investigatingvia llm_extracted
lexmarkvendor investigatingvia llm_extracted
libreofficevendor investigatingvia llm_extracted
postgresqlvendor investigatingvia llm_extracted
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: guest-images
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: rhel-guest-image

Vendor Advisories (6)

beegollm-beego-ebf0088f85be4332CRITICAL

[R1] Portable SDK for UPnP Devices (libupnp) glibc Implementation getaddrinfo() Function Remote Stack Overflow

Jan 27, 2017
postgresqlllm-postgresql-74df6c6bdcff57e4CRITICAL

[R1] Portable SDK for UPnP Devices (libupnp) glibc Implementation getaddrinfo() Function Remote Stack Overflow

Jan 27, 2017
lexmarkllm-lexmark-5a76a75ed589fd8eCRITICAL

[R1] Portable SDK for UPnP Devices (libupnp) glibc Implementation getaddrinfo() Function Remote Stack Overflow

Jan 26, 2017
libreofficellm-libreoffice-09e7b6e983c64786CRITICAL

[R1] Portable SDK for UPnP Devices (libupnp) glibc Implementation getaddrinfo() Function Remote Stack Overflow

Jan 26, 2017
redhatCVE-2015-7547Critical

glibc: getaddrinfo stack-based buffer overflow

Feb 16, 2016
latchsetllm-latchset-49c2f0d4426e1c6c

glibc getaddrinfo stack-based buffer overflow

Feb 9, 2016

References

fortiguard.com / advisory/glibc-getaddrinfo-stack-overflow
lists.fedoraproject.org / pipermail/package-announce/2016-February/177404.html
lists.fedoraproject.org / pipermail/package-announce/2016-February/177412.html
lists.opensuse.org / opensuse-security-announce/2016-02/msg00036.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00037.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00038.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00039.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00042.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00043.html
Third Party Advisory
lists.opensuse.org / opensuse-security-announce/2016-02/msg00044.html
Third Party Advisory
marc.info
marc.info
marc.info
marc.info
marc.info
packetstormsecurity.com / files/135802/glibc-getaddrinfo-Stack-Based-Buffer-Overflow.html
packetstormsecurity.com / files/154361/Cisco-Device-Hardcoded-Credentials-GNU-glibc-BusyBox.html
packetstormsecurity.com / files/164014/Moxa-Command-Injection-Cross-Site-Scripting-Vulnerable-Software.html
packetstormsecurity.com / files/167552/Nexans-FTTO-GigaSwitch-Outdated-Components-Hardcoded-Backdoor.html
rhn.redhat.com / errata/RHSA-2016-0175.html
rhn.redhat.com / errata/RHSA-2016-0176.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2016-0225.html
rhn.redhat.com / errata/RHSA-2016-0277.html
access.redhat.com / articles/2161461
Third Party Advisory
blogs.sophos.com / 2016/02/24/utm-up2date-9-355-released
Third Party Advisory
blogs.sophos.com / 2016/02/29/utm-up2date-9-319-released
Third Party Advisory
bto.bluecoat.com / security-advisory/sa114
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
seclists.org / fulldisclosure/2019/Sep/7
seclists.org / fulldisclosure/2021/Sep/0
seclists.org / fulldisclosure/2022/Jun/36
googleonlinesecurity.blogspot.com / 2016/02/cve-2015-7547-glibc-getaddrinfo-stack.html
h20566.www2.hpe.com / hpsc/doc/public/display
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
Third Party Advisory
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
h20566.www2.hpe.com / portal/site/hpsc/public/kb/docDisplay
help.ecostruxureit.com / display/public/UADCO8x/StruxureWare+Data+Center+Operation+Software+Vulnerability+Fixes
ics-cert.us-cert.gov / advisories/ICSA-16-103-01
kb.pulsesecure.net / articles/Pulse_Security_Advisories/SA40161
Third Party Advisory
kc.mcafee.com / corporate/index
Third Party Advisory
seclists.org / bugtraq/2019/Sep/7
security.gentoo.org / glsa/201602-02
Third Party Advisory
security.netapp.com / advisory/ntap-20160217-0002
sourceware.org / bugzilla/show_bug.cgi
Issue Tracking
sourceware.org / ml/libc-alpha/2016-02/msg00416.html
Mailing ListVendor Advisory
support.f5.com / kb/en-us/solutions/public/k/47/sol47098834.html
Third Party Advisory
support.lenovo.com / us/en/product_security/len_5450
support.citrix.com / article/CTX206991
arista.com / en/support/advisories-notices/security-advisories/1255-security-advisory-17
exploit-db.com / exploits/39454
exploit-db.com / exploits/40339
kb.cert.org / vuls/id/457759
tenable.com / security/research/tra-2017-08
ubuntu.com / usn/usn-2900-1
Third Party Advisory
debian.org / security/2016/dsa-3480
debian.org / security/2016/dsa-3481
Third Party Advisory
fortiguard.com / advisory/glibc-getaddrinfo-stack-overflow
huawei.com / en/psirt/security-advisories/huawei-sa-20160304-01-glibc-en
oracle.com / technetwork/security-advisory/cpuapr2016v3-2985753.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujan2018-3236628.html
oracle.com / technetwork/topics/security/linuxbulletinjan2016-2867209.html
securityfocus.com / bid/83265
securitytracker.com / id/1035020
vmware.com / security/advisories/VMSA-2016-0002.html