AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2015-20109

MEDIUM · CVSS 5.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-06-25 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2015-20109
Severity
MEDIUM
CVSS
5.5
EPSS
0.32%
Linux

Original NVD Description

end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this is not the same as CVE-2015-8984; also, some Linux distributions have fixed CVE-2015-8984 but have not fixed this additional fnmatch issue.