Possible mitigation, but might need to range 512: and the TCP rule might need to change to start from 1024
cve-2015-7547  glibc  security  mitigation  iptables  firewall  rule  oversize  DNS  packet  filter  Delicious 
february 2016

