The fnmatch function in the GNU C Library (aka glibc or libc6) before 2.22 might allow context-dependent attackers to cause a denial of service (application crash) via a malformed pattern, which triggers an out-of-bounds read. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8984