CVE-2015-5276: GNU Gcc
Medium severity, CVSS 5.0. EPSS: 2.9% chance of exploitation in the next 30 days.
The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent attackers to predict the random values via unspecified vectors.
Affected products
- GNU Gcc: before 4.9.4 (fixed in 4.9.4)
Published 2015-11-17. Last modified 2026-06-17.