← Vulnerability feed

Vulnerability record · CVE-2015-5477 · published 29 July 2015

CVE-2015-5477: ISC BIND TKEY Query Assertion Failure Denial of Service

Isc · Bind

ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 mishandle TKEY queries, triggering a REQUIRE assertion failure that terminates the named daemon. Because a single malformed query can take down a DNS server, this is a serious availability risk for any organization running an unpatched resolver or authoritative server.

7.8 CVSS 2.0 High EPSS 91% · top 0.2% CWE-19 · CWE-19
7.8CVSS 2.0 base score
91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
84References
17 Jun 2026Last modified by NVD

Description

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated remote crash of a core DNS service with very high EPSS, though no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 mishandle TKEY queries, triggering a REQUIRE assertion failure that terminates the named daemon. Because a single malformed query can take down a DNS server, this is a serious availability risk for any organization running an unpatched resolver or authoritative server.

Impact

A remote attacker can crash the named process, causing a denial of service for all DNS resolution or authoritative service handled by that instance. There is no confidentiality or integrity impact; only availability is affected.

Attack surface

The flaw is reachable over the network via a crafted TKEY query sent to the DNS service, as reflected by the AV:N/AC:L/Au:N vector. No authentication or user interaction is required, and the attacker only needs network reachability to the DNS port.

Exploitation

The record does not list this CVE in CISA KEV and provides no exploit tags, but EPSS is very high at 0.91284 (99.8th percentile), indicating strong predicted exploitation activity. No ransomware group usage is documented.

What to do

  • Upgrade to BIND 9.9.7-P2, 9.10.2-P3, or a later supported release immediately.
  • If immediate patching is not possible, restrict DNS service exposure to trusted networks and disable or filter TKEY queries where feasible.
  • Apply vendor errata for packaged BIND distributions (Red Hat, Debian, openSUSE, Oracle, Juniper) rather than building from source.
  • Monitor BIND vendor advisories and re-check for updated patches, since the record is marked Modified.

Detection

  • Alert on named process exits or restarts correlated with REQUIRE assertion failure messages in BIND logs.
  • Inspect DNS query logs for TKEY query types (QTYPE 249) from unexpected or external sources.
  • Use network monitoring to flag anomalous volumes of TKEY queries directed at DNS servers.
  • Track DNS service availability drops that coincide with inbound TKEY traffic.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://kb.juniper.net/InfoCenter/index?page=content&id=JSA10718
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163006.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163007.html
http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163015.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00043.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00044.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00045.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00048.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00050.html
http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00001.html
http://lists.opensuse.org/opensuse-security-announce/2016-01/msg00033.html
http://marc.info/?l=bugtraq&m=144000632319155&w=2
http://marc.info/?l=bugtraq&m=144017354030745&w=2
http://marc.info/?l=bugtraq&m=144181171013996&w=2
http://marc.info/?l=bugtraq&m=144294073801304&w=2
http://packetstormsecurity.com/files/132926/BIND-TKEY-Query-Denial-Of-Service.html
http://rhn.redhat.com/errata/RHSA-2015-1513.html
http://rhn.redhat.com/errata/RHSA-2015-1514.html
http://rhn.redhat.com/errata/RHSA-2015-1515.html
http://rhn.redhat.com/errata/RHSA-2016-0078.html
http://rhn.redhat.com/errata/RHSA-2016-0079.html
http://www.debian.org/security/2015/dsa-3319
http://www.oracle.com/technetwork/topics/security/bulletinjul2015-2511963.html
http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html
http://www.securityfocus.com/bid/76092
http://www.securitytracker.com/id/1033100
http://www.ubuntu.com/usn/USN-2693-1
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04789415
https://h20564.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c04952480
https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05095918
https://kb.isc.org/article/AA-01272 PatchVendor Advisory
https://kb.isc.org/article/AA-01305
https://kb.isc.org/article/AA-01306
https://kb.isc.org/article/AA-01307
https://kb.isc.org/article/AA-01438
https://kb.juniper.net/JSA10783
https://kc.mcafee.com/corporate/index?page=content&id=SB10126
https://security.gentoo.org/glsa/201510-01
https://security.netapp.com/advisory/ntap-20160114-0001/
https://support.apple.com/kb/HT205032

Track CVE-2015-5477 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2015-5477), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.