CVE-2015-20109

unknown
Published — · Modified —
CVSS v3
CVSS v2
VIR risk

Description

end_pattern (called from internal_fnmatch) in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash), as demonstrated by use of the fnmatch library function with the **(!() pattern. NOTE: this is not the same as CVE-2015-8984; also, some Linux distributions have fixed CVE-2015-8984 but have not fixed this additional fnmatch issue.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2015-20109

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed2.22-1
debian debianbullseyefixed2.22-1
debian debianforkyfixed2.22-1
debian debiansidfixed2.22-1
debian debiantrixiefixed2.22-1

References

Verify integrity in audit chain (admin only). AS-IS.