CVE-2015-5477: ISC BIND Data Processing Errors Vulnerability
High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2026-10-08. EPSS: 99.4% chance of exploitation in the next 30 days.
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.
Affected products
- Apple OS X Server: version 4.1.5 only
- Canonical Ubuntu Linux: version 12.04 only
- Debian Debian Linux: version 7.0 only; version 8.0 only
- Fedoraproject Fedora: version 21 only; version 22 only
- HP HP-Ux: version 11.11 only; version 11.23 only; version 11.31 only
- HP Openvms: version 5.7 only
- HPE DNS: version 9.2.3 only; version 9.3 only
- HPE Vcx: before 9.8.18 (fixed in 9.8.18)
- ISC BIND: from 9.1.0, before 9.9.7 (fixed in 9.9.7); from 9.10.0, before 9.10.2 (fixed in 9.10.2); version 9.10.2 only
- Juniper Junos: before 12.1 (fixed in 12.1); from 13.1, before 13.2 (fixed in 13.2); version 12.1 only; version 12.1r only; version 12.1x44 only; version 12.1x45 only; …
- Netapp Clustered Data Ontap: affected versions not specified
- Opensuse Evergreen: version 11.4 only
- Opensuse Opensuse: version 13.1 only; version 13.2 only
- Oracle Solaris: version 10 only; version 11.2 only
- Oracle Vm Server: version 3.2 only
- Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only
- Red Hat Enterprise Linux Aus: version 6.4 only; version 6.5 only; version 6.6 only
- Suse Linux Enterprise Debuginfo: version 11 only
- Suse Linux Enterprise Desktop: version 11 only; version 12 only
- Suse Linux Enterprise Server: version 10 only; version 11 only; version 12 only
- Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only
Published 2015-07-29. Last modified 2026-10-09.