CVE-2015-7547 is a stack-based buffer overflow in the GNU C Library (glibc) resolver path, specifically in the libresolv library functions send_dg and send_vc, affecting glibc before 2.23. The flaw is reachable through getaddrinfo() when it performs dual A/AAAA DNS queries using the AF_UNSPEC or AF_INET6 address family via the libnss_dns.so.2 NSS module. A crafted DNS response can trigger memory corruption on the stack, causing process crashes and potentially enabling arbitrary code execution in the context of the calling process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository provides a proof-of-concept (PoC) exploit for CVE-2015-7547, a buffer overflow vulnerability in the glibc getaddrinfo() function. The repository contains two main code files: a Python script (CVE-2015-7547-poc.py) that acts as a malicious DNS server, and a C client (CVE-2015-7547-client.c) that performs a DNS query using getaddrinfo(). The exploit works by configuring the target system to use the PoC Python server as its DNS server. When the client code (or any application using getaddrinfo()) queries a domain (e.g., foo.bar.google.com), the malicious server sends specially crafted DNS responses that trigger the buffer overflow, causing the client to crash. The Makefile is provided to compile the client code. The README explains the setup and warns about the risks of running the PoC. This exploit demonstrates a denial-of-service (DoS) condition and is intended for testing and research purposes.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.