suse · CVE-2015-5276

Quick triage

Priority: low Published: 2021-05-30 13:31:55 UTC Updated: 2026-04-20 08:43:31 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2015-5276 severity low: SUSE including 517 source package names (0.9.1:libffi4-5.3.1+r233831-9.1, 0.9.1:libgcc_s1-5.3.1+r233831-9.1, …), 1896 product×package rows across 98 product lines (Container caasp/v4/default-http-backend, Container caasp/v4/dnsmasq-nanny, … (98 product lines)): Fixed 1016, Known Not Affected 880.

Description:

The std::random_device class in libstdc++ in the GNU Compiler Collection (aka GCC) before 4.9.4 does not properly handle short reads from blocking sources, which makes it easier for context-dependent attackers to predict the random values via unspecified vectors.

cvelogic Threat Intelligence