CVE-2015-5477: ISC BIND Data Processing Errors Vulnerability

High severity, CVSS 7.5. Actively exploited: in CISA KEV since 2026-10-08. EPSS: 99.4% chance of exploitation in the next 30 days.

named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (REQUIRE assertion failure and daemon exit) via TKEY queries.

Affected products

  • Apple OS X Server: version 4.1.5 only
  • Canonical Ubuntu Linux: version 12.04 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only
  • Fedoraproject Fedora: version 21 only; version 22 only
  • HP HP-Ux: version 11.11 only; version 11.23 only; version 11.31 only
  • HP Openvms: version 5.7 only
  • HPE DNS: version 9.2.3 only; version 9.3 only
  • HPE Vcx: before 9.8.18 (fixed in 9.8.18)
  • ISC BIND: from 9.1.0, before 9.9.7 (fixed in 9.9.7); from 9.10.0, before 9.10.2 (fixed in 9.10.2); version 9.10.2 only
  • Juniper Junos: before 12.1 (fixed in 12.1); from 13.1, before 13.2 (fixed in 13.2); version 12.1 only; version 12.1r only; version 12.1x44 only; version 12.1x45 only; …
  • Netapp Clustered Data Ontap: affected versions not specified
  • Opensuse Evergreen: version 11.4 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only
  • Oracle Solaris: version 10 only; version 11.2 only
  • Oracle Vm Server: version 3.2 only
  • Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Enterprise Linux Aus: version 6.4 only; version 6.5 only; version 6.6 only
  • Suse Linux Enterprise Debuginfo: version 11 only
  • Suse Linux Enterprise Desktop: version 11 only; version 12 only
  • Suse Linux Enterprise Server: version 10 only; version 11 only; version 12 only
  • Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only

Published 2015-07-29. Last modified 2026-10-09.