CVE-2015-5276

The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent attackers to predict the random values via unspecified vectors.

Published: 2015-11-17 Last update: 2026-05-06 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2015-5276 is rated Moderate Risk (52.5/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 2.94%). Core evidence: EPSS rose +2.64% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2015-5276

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.30% 2.94% +2.64%
2 2026-06-14 0.45% 0.30% -0.15%
3 2025-07-12 0.45%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2015-5276

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
5.0 2.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
10.0 2.9 [email protected]

Weakness enumeration for CVE-2015-5276

OS Trackers for CVE-2015-5276

vendor priority summary link
redhat low https://access.redhat.com/security/cve/CVE-2015-5276
suse low CVE-2015-5276 severity low: SUSE including 517 source package names (0.9.1:libffi4-5.3.1+r233831-9.1, 0.9.1:libgcc_s1-5.3.1+r233831-9.1, …), 1896 product×package rows across 98 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (98 product lines)): Fixed 1016, Known Not Affected 880. https://www.suse.com/security/cve/CVE-2015-5276/
ubuntu low CVE-2015-5276 low priority: Ubuntu including 46 source packages (gcc-3.3, gcc-4.4, …), 1150 status rows across 25 suites (artful, bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, precise, questing, trusty, upstream, vivid, wily, xenial, yakkety, zesty): DNE 796, not-affected 199, ignored 103, needed 33, needs-triage 15, released 4. https://ubuntu.com/security/CVE-2015-5276

Affected software / configurations for CVE-2015-5276

Vendor Product Version Raw CPE
gnu gcc < 4.9.4 cpe:2.3:a:gnu:gcc:*:*:*:*:*:*:*:*

References for CVE-2015-5276

URL Tags
http://lists.opensuse.org/opensuse-updates/2015-11/msg00054.html Mailing List Third Party Advisory
http://lists.opensuse.org/opensuse-updates/2016-04/msg00052.html Mailing List Third Party Advisory
http://www.securitytracker.com/id/1034375 Third Party Advisory VDB Entry
https://bugzilla.redhat.com/show_bug.cgi?id=1262846 Issue Tracking Third Party Advisory
https://gcc.gnu.org/bugzilla/show_bug.cgi?id=65142 Issue Tracking Vendor Advisory
cvelogic Threat Intelligence