CVE-2015-8985: GNU Glibc

Medium severity, CVSS 5.9. EPSS: 2.9% chance of exploitation in the next 30 days.

The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to extended regular expression processing.

Affected products

  • GNU Glibc: before 2.28 (fixed in 2.28)

Published 2017-03-20. Last modified 2026-06-17.