CVE-2016-1285: Canonical Ubuntu Linux

Medium severity, CVSS 6.8. EPSS: 59.1% chance of exploitation in the next 30 days.

named in ISC BIND 9.x before 9.9.8-P4 and 9.10.x before 9.10.3-P4 does not properly handle DNAME records when parsing fetch reply messages, which allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a malformed packet to the rndc (aka control channel) interface, related to alist.c and sexpr.c.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only; version 15.10 only
  • Debian Debian Linux: version 7.0 only; version 8.0 only; version 9.0 only
  • Fedoraproject Fedora: version 22 only; version 23 only; version 24 only
  • ISC BIND: from 9.0.0, before 9.9.8 (fixed in 9.9.8); from 9.10.0, before 9.10.3 (fixed in 9.10.3); version 9.9.8 only; version 9.10.3 only
  • Juniper Junos: version 12.1x46 only; version 12.1x46-d10 only; version 12.1x46-d76 only; version 12.3x48 only; version 15.1x49 only; version 17.3 only; …
  • Opensuse Leap: version 42.1 only
  • Opensuse Opensuse: version 11.4 only; version 13.1 only; version 13.2 only
  • Suse Linux Enterprise Debuginfo: version 11 only
  • Suse Linux Enterprise Desktop: version 11 only; version 12 only
  • Suse Linux Enterprise Server: version 11 only; version 12 only
  • Suse Linux Enterprise Software Development Kit: version 11 only; version 12 only
  • Suse Manager: version 2.1 only
  • Suse Manager Proxy: version 2.1 only
  • Suse Openstack Cloud: version 5 only

Published 2016-03-09. Last modified 2026-06-17.