Skip to content
firewallpulse
Bits, bytes and breaking security news
Vulnerabilities

BIND TKEY DoS Bug: US Gov Sets Oct 11 Deadline for Patching Affected Servers

The US government has added CVE-2015-5477 to its catalog, requiring teams to mitigate the high-severity remote DoS vulnerability within three days.

BIND TKEY DoS Bug: US Gov Sets Oct 11 Deadline for Patching Affected Servers
Illustration: Firewall Pulse

Key points

  • CVE-2015-5477 allows remote attackers to crash BIND servers via TKEY queries.
  • The flaw affects BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3.
  • CISA sets a federal compliance deadline of 11 October 2026.

The US Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2015-5477 to its Known Exploited Vulnerabilities (KEV) catalog. This action mandates that federal agencies and connected contractors apply mitigations for a denial of service vulnerability in ISC BIND by 11 October 2026. The entry highlights a persistent risk in widely deployed DNS infrastructure.

Root cause

The vulnerability stems from data processing errors within the BIND software. According to the National Vulnerability Database (NVD), the issue allows remote attackers to trigger a REQUIRE assertion failure. This internal error causes the BIND daemon to exit unexpectedly, resulting in a complete denial of service. The NVD classifies the weaknesses using CWE-19 (Information Exposure Through a Directory Listing) and CWE-617 (Synchronization Error in a Multithreaded Context).

Attack path

Attackers exploit this flaw by sending specific TKEY queries to the affected DNS server. TKEY is a mechanism used for establishing secret keys between DNS servers. The malformed or targeted queries trigger the assertion failure without requiring authentication. Because the attack is remote and does not require prior access, any internet-facing BIND server running vulnerable code is at risk of being taken offline.

Affected versions

The NVD record specifies the following versions are affected:

  • ISC BIND 9.x versions prior to 9.9.7-P2
  • ISC BIND 9.x versions prior to 9.10.2-P3

Mitigation

CISA requires stakeholders to apply mitigations in accordance with vendor instructions. Teams must ensure compliance with CISA’s Binding Operational Directive (BOD) 26-04, which prioritises security updates based on risk. If mitigations are unavailable, CISA advises discontinuing use of the product. Organisations using cloud services must follow applicable BOD 26-04 guidance. Stakeholders are responsible for evaluating each asset's internet exposure.

What to do and how to stay safe: ISC BIND

  • Inventory all DNS servers to identify those running BIND 9.x versions older than 9.9.7-P2 or 9.10.2-P3.
  • Restrict access to TKEY functionality if it is not required for your DNS zone management operations.
  • Monitor system logs for unexpected daemon exits or assertion failures that may indicate exploitation attempts.
  • Review network segmentation to ensure internet-facing DNS servers are isolated from critical internal systems.

General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is the CVSS score for CVE-2015-5477?

The NVD rates the vulnerability as HIGH with a CVSS score of 7.5.

Is there a confirmed ransomware link to this vulnerability?

CISA lists the ransomware use status as Unknown in its KEV catalog entry.

What is the federal deadline for mitigation?

The federal due date is 11 October 2026.

Sources

  1. CISA KEV catalog
ISC BINDCVE-2015-5477CISADNSDoS

Related stories