ISC BIND Data Processing Errors Vulnerability
TL;DR 📌
- ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.
- Listed in CISA KEV (2026-10-08) — this is being exploited in the wild.
- Check the advisory for fixed releases — remediation detail is in the vendor link below.
- CVEs: CVE-2015-5477.
What it is
CVE-2015-5477 is a data-processing flaw in ISC BIND’s named daemon, triggered by TKEY queries. TKEY is part of BIND’s DNS protocol handling used for key exchange.
A remote attacker needs only to send a crafted TKEY query to a vulnerable named instance over the DNS service port; no authentication is required. The query causes a REQUIRE assertion failure inside named, which results in the daemon exiting. This is a denial-of-service condition against the DNS resolver/server process itself, not a path to code execution or data disclosure.
The flaw affects BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3. Versions 9.9.7 and 9.10.2 are listed as the last vulnerable releases in those branches, so anything prior to the patched point releases above should be treated as exposed.
This CVE is listed in CISA’s Known Exploited Vulnerabilities catalogue, added 2026-10-08.
What to do
- Identify all authoritative and recursive BIND installations and check
named -voutput against the affected ranges (9.9.x before 9.9.7-P2, 9.10.x before 9.10.2-P3). - Upgrade to a release past 9.9.7-P2 or 9.10.2-P3 as appropriate for your branch; the advisory should be consulted for the exact current recommended build, since no specific fixed version string beyond the P2/P3 point releases is given here.
- Where immediate patching isn’t possible, restrict access to the DNS service port to trusted sources to reduce exposure to unsolicited TKEY queries.
- Given this CVE’s presence in the CISA KEV catalogue, prioritise remediation on internet-facing authoritative and resolving name servers first.
- After patching, confirm
namedstability by monitoring for unexpected process restarts or assertion-failure log entries, which would indicate exploitation attempts against the unpatched behaviour.
For leadership 🧭
Executive summary. Any internet-facing BIND server running a version before 9.9.7-P2 or 9.10.2-P3 can be knocked offline by an unauthenticated attacker sending one malformed DNS query. This is now listed as a known exploited vulnerability, so authoritative and recursive name servers should be patched or shielded this week, not next quarter.
Why it matters:
- The flaw sits in named’s TKEY query handling, meaning anyone who can reach the DNS service port can trigger a REQUIRE assertion failure and crash the daemon with no credentials.
- Affected ranges cover BIND 9.9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3, so any installation at or below 9.9.7 or 9.10.2 proper is still exposed.
- A crashed named process means DNS resolution or authoritative answers stop entirely for whatever zones or clients that server handles, until it is manually or automatically restarted.
- Inclusion in CISA’s KEV catalogue means this specific crash condition is being treated as a live exploitation risk, not a theoretical one.
Now / Next / Later:
- Now: Run named -v against every authoritative and recursive BIND instance and flag anything on 9.9.x before 9.9.7-P2 or 9.10.x before 9.10.2-P3 as exposed.
- Next: Patch flagged servers to a build past 9.9.7-P2 or 9.10.2-P3 in the next change window, prioritising internet-facing authoritative and resolving name servers.
- Later: Restrict DNS service port access to trusted sources where patching lags, and add monitoring for named process restarts or assertion-failure log entries to catch future TKEY-style crash attempts early.