CVE-2012-5689: Canonical Ubuntu Linux

High severity, CVSS 7.1. EPSS: 12% chance of exploitation in the next 30 days.

ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for an AAAA record.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.04 only
  • ISC BIND: version 9.9.0 only; version 9.9.1 only; version 9.9.2 only; version 9.8.0 only; version 9.8.1 only; version 9.8.2 only; …
  • Red Hat Enterprise Linux Desktop: version 6.0 only
  • Red Hat Enterprise Linux Hpc Node: version 6.0 only
  • Red Hat Enterprise Linux Server: version 6.0 only
  • Red Hat Enterprise Linux Server Aus: version 6.4 only
  • Red Hat Enterprise Linux Server Eus: version 6.4.z only
  • Red Hat Enterprise Linux Workstation: version 6.0 only

Published 2013-01-25. Last modified 2026-06-16.