Cyber & AI intelligence
Wasteland.
Briefs indexed3090
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2015-5477 2026-10-08

CVE-2015-5477: CISA Confirms Active Exploitation of a Decade-Old ISC BIND TKEY Denial-of-Service Flaw

"CISA added CVE-2015-5477 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-10-08. The flaw dates from 2015 and affects ISC BIND. A remote attacker with no credentials can crash the `named` DNS daemon by…"

CISA added CVE-2015-5477 to its Known Exploited Vulnerabilities (KEV) catalog on 2026-10-08. The flaw dates from 2015 and affects ISC BIND. A remote attacker with no credentials can crash the named DNS daemon by sending TKEY queries.

What Is It

CVE-2015-5477 is a denial-of-service vulnerability in named, the server daemon in ISC BIND. According to NVD, remote attackers can send TKEY queries that trigger a REQUIRE assertion failure, and the failure makes the daemon exit. CISA lists the flaw as "ISC BIND Data Processing Errors Vulnerability" (CWE-19). A secondary CNA assessment maps it to CWE-617 (Reachable Assertion). NVD first published the CVE on 2015-07-29.

Why It Matters

What's Vulnerable

NVD lists these affected versions:

Products that bundle BIND may also be affected. Juniper published a Junos security bulletin for this CVE, and Red Hat, Debian and Ubuntu issued advisories.

Patch Status

ISC's advisory AA-01272 is tagged as a patch and vendor advisory. Per NVD, the fixed releases are BIND 9.9.7-P2 and 9.10.2-P3.

For agencies covered by BOD 26-04 (Prioritizing Security Updates Based on Risk), CISA's required action is to apply mitigations according to vendor instructions and to follow CISA's Forensics Triage Requirements. If no mitigations are available, the directive tells these agencies to follow the BOD 26-04 guidance for cloud services or stop using the product. Covered agencies must also assess each asset's internet exposure. KEV marks forensic triage for this entry as "No." These requirements apply to federal agencies only, but other organizations can use them as a model for their own response.

Organizations still running these BIND versions, whether directly or inside appliances and distributions, should apply vendor or distribution updates promptly. Federal agencies covered by BOD 26-04 must do so by 2026-10-11. Other organizations can use that date as a benchmark, especially for internet-facing resolvers and authoritative servers.

Sources