CVE-2016-1285: Canonical Ubuntu Linux
Medium severity, CVSS 6.8. EPSS: 59.1% chance of exploitation in the next 30 days.
named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
- Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
- Fedoraproject Fedora: version 22 only; version 23 only; version 24 only
- ISC BIND: from 9.0.0, before 9.9.8 (fixed in 9.9.8); from 9.10.0, before 9.10.3 (fixed in 9.10.3); version 9.9.8 only; version 9.10.3 only
- Juniper Junos: version 12.1x46 only; version 12.1x46-d10 only; version 12.1x46-d76 only; version 12.3x48 only; version 15.1x49 only; version 17.3 only; …
- Opensuse Leap: version 42.1 only
- Opensuse Opensuse: version 11.4 only; version 13.1 only; version 13.2 only
- Suse Linux Enterprise Debuginfo: version 11 only
- Suse Linux Enterprise Desktop: version 11 only; version 12 only
- Suse Linux Enterprise Server: version 11 only; version 12 only
- Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only
- Suse Manager: version 2.1 only
- Suse Manager Proxy: version 2.1 only
- Suse Openstack Cloud: version 5 only
Published 2016-03-09. Last modified 2026-06-17.