CVE-2015-7547: Canonical Ubuntu Linux

High severity, CVSS 8.1. EPSS: 91% chance of exploitation in the next 30 days.

Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted DNS response that triggers a call to the getaddrinfo function with the AF_UNSPEC or AF_INET6 address family, related to performing "dual A/AAAA DNS queries" and the libnss_dns.so.2 NSS module.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
  • Debian Debian Linux: version 8.0 only
  • F5 BIG-IP Access Policy Manager: version 12.0.0 only
  • F5 BIG-IP Advanced Firewall Manager: version 12.0.0 only
  • F5 BIG-IP Analytics: version 12.0.0 only
  • F5 BIG-IP Application Acceleration Manager: version 12.0.0 only
  • F5 BIG-IP Application Security Manager: version 12.0.0 only
  • F5 BIG-IP Domain Name System: version 12.0.0 only
  • F5 BIG-IP Link Controller: version 12.0.0 only
  • F5 BIG-IP Local Traffic Manager: version 12.0.0 only
  • F5 BIG-IP Policy Enforcement Manager: version 12.0.0 only
  • GNU Glibc: version 2.9 only; version 2.10 only; version 2.10.1 only; version 2.11 only; version 2.11.1 only; version 2.11.2 only; …
  • HP Helion Openstack: version 1.1.1 only; version 2.0.0 only; version 2.1.0 only
  • HP Server Migration Pack: version 7.5 only
  • Opensuse Opensuse: version 13.2 only
  • Oracle Exalogic Infrastructure: version 1.0 only; version 2.0 only
  • Oracle Fujitsu m10 Firmware: up to and including 2290
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux Hpc Node: version 7.0 only
  • Red Hat Enterprise Linux Hpc Node Eus: version 7.2 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Server Aus: version 7.2 only
  • Red Hat Enterprise Linux Server Eus: version 7.2 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Sophos Unified Threat Management Software: version 9.319 only; version 9.355 only
  • and 5 more

Published 2016-02-18. Last modified 2026-06-17.