Vulnerability record · CVE-2015-5311 · published 17 November 2015
CVE-2015-5311: PowerDNS Authoritative Server crash via crafted query packets
Powerdns · Authoritative
PowerDNS Authoritative Server versions 3.4.4 up to but not including 3.4.7 fail to properly validate crafted query packets, triggering an assertion failure that crashes the server. Because the authoritative server is the DNS resolver of record for its zones, a crash takes those zones offline until the process restarts.
Description
PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityThe flaw is remotely exploitable without authentication and crashes a core DNS service, and the high EPSS score suggests active interest despite no KEV listing.
What it is
PowerDNS Authoritative Server versions 3.4.4 up to but not including 3.4.7 fail to properly validate crafted query packets, triggering an assertion failure that crashes the server. Because the authoritative server is the DNS resolver of record for its zones, a crash takes those zones offline until the process restarts.
Impact
A remote unauthenticated attacker can cause a denial of service by crashing the PowerDNS process, interrupting DNS resolution for all zones it serves. No data confidentiality or integrity impact is described; the effect is availability loss.
Attack surface
Reachable over the network via the DNS service port, as reflected by the AV:N/AC:L/Au:N vector. No authentication or user interaction is required; the attacker only needs to send a crafted query packet to the server.
Exploitation
Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.67 (99th percentile), indicating elevated likelihood of exploitation activity. The vendor advisory is tagged Patch and Vendor Advisory, confirming a fix exists.
What to do
- Upgrade PowerDNS Authoritative Server to 3.4.7 or later per the vendor advisory powerdns-advisory-2015-03.
- If immediate upgrade is not possible, restrict DNS query access to trusted networks and clients via firewall or ACL rules.
- Run the authoritative server under a supervisor or service manager that automatically restarts it after a crash to limit outage duration.
- Monitor vendor and distribution package announcements for backported fixes if running a packaged build.
Detection
- Monitor PowerDNS process logs for assertion failures or unexpected restarts and correlate with inbound query traffic.
- Alert on abrupt termination or restart events of the pdns service outside planned maintenance windows.
- Baseline DNS query patterns and flag unusual or malformed query packets directed at the authoritative server.
- Track availability gaps in DNS responses for zones served by the affected instance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-5311 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-5311), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.