Vulnerability record · CVE-2015-0235 · published 28 January 2015
CVE-2015-0235: glibc gethostbyname heap buffer overflow (GHOST)
Gnu · Glibc
CVE-2015-0235 is a heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2 and other 2.x versions before 2.18. It is reachable through the gethostbyname and gethostbyname2 functions, so any application that resolves a hostname with attacker-influenced input can trigger it. Because glibc is a core system library, the flaw affects a very wide range of Linux and Unix-like software.
Description
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score is 10.0 with complete confidentiality, integrity and availability impact, the flaw is remotely reachable without authentication, and public exploit references exist.
What it is
CVE-2015-0235 is a heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2 and other 2.x versions before 2.18. It is reachable through the gethostbyname and gethostbyname2 functions, so any application that resolves a hostname with attacker-influenced input can trigger it. Because glibc is a core system library, the flaw affects a very wide range of Linux and Unix-like software.
Impact
A context-dependent attacker can execute arbitrary code in the process that performs the name resolution, or at minimum crash it. Successful exploitation gives the attacker the privileges of the vulnerable service, which is often root or a network-facing daemon.
Attack surface
Reached remotely over the network through applications that call gethostbyname or gethostbyname2 on attacker-controlled hostnames, such as mail servers and other network services. No authentication is required per the CVSS vector AV:N/AC:L/Au:N, though the attacker must be able to influence the hostname being resolved.
Exploitation
CISA KEV does not list it, but EPSS is very high at 0.94558 (99.85th percentile) and multiple references are tagged Exploit, including Packet Storm and Full Disclosure entries, indicating public exploit material exists.
What to do
- Patch glibc to version 2.18 or later, or apply the vendor backport for your distribution (Red Hat, Debian, Oracle, Apple, IBM advisories are referenced).
- Restart all services and processes that link glibc after patching, since the vulnerable code is loaded into running processes.
- Where patching is not immediately possible, restrict or filter attacker-controlled hostnames reaching gethostbyname/gethostbyname2 callers.
- Inventory and prioritize network-facing services that resolve hostnames from untrusted input, such as mail and web servers.
- Monitor vendor advisories for embedded and appliance products that bundle glibc and may lag behind upstream fixes.
Detection
- Hunt for processes and services that call gethostbyname or gethostbyname2 with externally supplied hostnames.
- Monitor for crashes or abnormal termination in name-resolution paths that could indicate exploitation attempts.
- Check glibc package versions across hosts and flag any still below 2.18 or missing the vendor backport.
- Review network logs for unusual or malformed hostname lookups directed at vulnerable services.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
18 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-0235 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-0235), CISA KEV, FIRST EPSS (scores of 2026-09-23). This page is refreshed as NVD updates the record.