CVE-2015-7547: Canonical Ubuntu Linux
High severity, CVSS 8.1. EPSS: 91% chance of exploitation in the next 30 days.
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
- Debian Debian Linux: version 8.0 only
- F5 BIG-IP Access Policy Manager: version 12.0.0 only
- F5 BIG-IP Advanced Firewall Manager: version 12.0.0 only
- F5 BIG-IP Analytics: version 12.0.0 only
- F5 BIG-IP Application Acceleration Manager: version 12.0.0 only
- F5 BIG-IP Application Security Manager: version 12.0.0 only
- F5 BIG-IP Domain Name System: version 12.0.0 only
- F5 BIG-IP Link Controller: version 12.0.0 only
- F5 BIG-IP Local Traffic Manager: version 12.0.0 only
- F5 BIG-IP Policy Enforcement Manager: version 12.0.0 only
- GNU Glibc: version 2.9 only; version 2.10 only; version 2.10.1 only; version 2.11 only; version 2.11.1 only; version 2.11.2 only; …
- HP Helion Openstack: version 1.1.1 only; version 2.0.0 only; version 2.1.0 only
- HP Server Migration Pack: version 7.5 only
- Opensuse Opensuse: version 13.2 only
- Oracle Exalogic Infrastructure: version 1.0 only; version 2.0 only
- Oracle Fujitsu m10 Firmware: up to and including 2290
- Red Hat Enterprise Linux Desktop: version 7.0 only
- Red Hat Enterprise Linux Hpc Node: version 7.0 only
- Red Hat Enterprise Linux Hpc Node Eus: version 7.2 only
- Red Hat Enterprise Linux Server: version 7.0 only
- Red Hat Enterprise Linux Server Aus: version 7.2 only
- Red Hat Enterprise Linux Server Eus: version 7.2 only
- Red Hat Enterprise Linux Workstation: version 7.0 only
- Sophos Unified Threat Management Software: version 9.319 only; version 9.355 only
- and 5 more
Published 2016-02-18. Last modified 2026-06-17.