The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent attackers to predict the random values via unspecified vectors.
Conclusion & alert: CVE-2015-5276 is rated Moderate Risk (52.5/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.94%). Core evidence: EPSS rose +2.64% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.30% | 2.94% | +2.64% |
| 2 | 2026-06-14 | 0.45% | 0.30% | -0.15% |
| 3 | 2025-07-12 | — | 0.45% | — |
Full EPSS history (10 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2015-5276 |
suse
|
low | CVE-2015-5276 severity low: SUSE including 517 source package names (0.9.1:libffi4-5.3.1+r233831-9.1, 0.9.1:libgcc_s1-5.3.1+r233831-9.1, …), 1896 product×package rows across 98 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (98 product lines)): Fixed 1016, Known Not Affected 880. | https://www.suse.com/security/cve/CVE-2015-5276/ |
ubuntu
|
low | CVE-2015-5276 low priority: Ubuntu including 46 source packages (gcc-3.3, gcc-4.4, …), 1150 status rows across 25 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, precise, questing, trusty, upstream, vivid, wily, xenial, yakkety, zesty): DNE 796, not-affected 199, ignored 103, needed 33, needs-triage 15, released 4. | https://ubuntu.com/security/CVE-2015-5276 |
| URL | Tags |
|---|---|
| http://lists.opensuse.org/opensuse-updates/2015-11/msg00054.html | Mailing List Third Party Advisory |
| http://lists.opensuse.org/opensuse-updates/2016-04/msg00052.html | Mailing List Third Party Advisory |
| http://www.securitytracker.com/id/1034375 | Third Party Advisory VDB Entry |
| https://bugzilla.redhat.com/show_bug.cgi?id=1262846 | Issue Tracking Third Party Advisory |
| https://gcc.gnu.org/bugzilla/show_bug.cgi?id=65142 | Issue Tracking Vendor Advisory |