SECURITYHIGHCVE-2015-5477

CVE-2015-5477: Decade-Old ISC BIND TKEY Flaw Added to CISA's KEV Catalog

A 2015 reachable-assertion DoS bug in ISC BIND's TKEY handling hit CISA's KEV catalog Oct. 8, 2026 after Flax Typhoon exploitation; patch by Oct. 11.

Dylan H.

Security Team

October 9, 2026
6 min read
CVE-2015-5477: Decade-Old ISC BIND TKEY Flaw Added to CISA's KEV Catalog

Actively exploited

Reported as exploited in the wild (e.g. CISA KEV). Patch or mitigate immediately.

Affected Products

  • ISC BIND 9 — versions 9.1.0 through 9.9.7-P1 (≤ 9.9.7-P1)
  • ISC BIND 9 — versions 9.10.0 through 9.10.2-P2 (≤ 9.10.2-P2)

Overview

An 11-year-old denial-of-service flaw in ISC BIND, the most widely deployed DNS server software on the internet, was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on October 8, 2026, with a federal remediation deadline of October 11, 2026. Tracked as CVE-2015-5477, the bug is a data processing / reachable assertion error in how named — BIND's core server daemon — handles TKEY resource records, letting a remote attacker crash the process with a single crafted DNS query.

The flaw was originally disclosed by ISC in July 2015 and carries a CVSS v2 score of 7.8, scored by CISA in this KEV addition at 7.5. It is being treated as a High severity issue on the Labs scale. What makes a decade-old bug newsworthy in 2026 is the reason it was added now: CISA ties its addition to active exploitation by Flax Typhoon (also tracked as RedJuliett and Ethereal Panda), the China-linked group behind the Integrity Technology Group stolen-email-access portal exposed in a joint FBI/CISA/NSA advisory the same week. CVE-2015-5477 was one of five newly KEV-listed flaws — alongside bugs in ProFTPD, ONLYOFFICE Docs, Strapi, and Apache Struts — out of eight total vulnerabilities the advisory says Flax Typhoon's operators have used for initial access and data exfiltration.


Technical Details

AttributeValue
CVE IDCVE-2015-5477
SeverityHigh
CVSS v2 Score7.8 (AV:N/AC:L/Au:N/C:N/I:N/A:C)
CVSS Score (per CISA KEV, Oct 2026)7.5
CWE ClassReachable Assertion / Data Processing Errors
Vendor / ProjectInternet Systems Consortium (ISC) / BIND
Vulnerable Componentnamed daemon — TKEY resource record handling
Affected VersionsBIND 9.1.0 through 9.9.7-P1 (≤ 9.9.7-P1); BIND 9.10.0 through 9.10.2-P2 (≤ 9.10.2-P2)
Fixed VersionsBIND 9.9.7-P2 or BIND 9.10.2-P3 and later
Attack VectorNetwork, low complexity, no authentication, no user interaction
Date Added to CISA KEVOctober 8, 2026
Federal Remediation DueOctober 11, 2026
Exploit StatusConfirmed exploited in the wild (Flax Typhoon); public Metasploit module and proof-of-concept exploits available
Original DisclosureJuly 28, 2015 (ISC Knowledge Base AA-01272)

How It Works

TKEY records are a BIND mechanism for negotiating shared transaction keys used in dynamic DNS updates. ISC's original advisory describes the root cause as an error in how named validates incoming TKEY queries: a specially crafted record can trip a REQUIRE assertion deep in BIND's packet-handling code, which the software treats as an unrecoverable internal-consistency failure and responds to by terminating the process outright.

Two details made this bug unusually severe even in 2015, and still relevant today:

  • Both authoritative and recursive servers are vulnerable — the flaw sits in generic packet-parsing logic exercised by any named instance that accepts DNS queries, not a feature limited to one server role.
  • Access controls do not help. The vulnerable code path executes before BIND evaluates ACLs or other configuration options meant to restrict who can query the server, so firewalling query access down to trusted hosts does not prevent an attacker who can reach port 53 at all from crashing the daemon.

A single malformed TKEY query is sufficient — there is no need for an ongoing flood, amplification, or spoofing technique. Each successful crash simply takes the resolver or authoritative server offline until something restarts it, making this a textbook crash-and-repeat denial-of-service primitive.


Why a 2015 Bug Matters in 2026

CVE-2015-5477 has had a patch available for over a decade, and the only reason it is appearing in a 2026 advisory is that unpatched BIND installations still exist in the wild and are being targeted by a capable, patient adversary. CISA's joint advisory links this specific KEV addition to Flax Typhoon's broader campaign against government, healthcare, critical-manufacturing, and education targets across Southeast Asia and beyond — the same operation tied to the Integrity Technology Group portal that gave third parties access to archived stolen email. Legacy, internet-facing DNS infrastructure that was never upgraded past BIND 9.10.2-P2 is exactly the kind of soft target that lets a state-aligned actor achieve easy, repeatable disruption without burning a zero-day.

This is a useful reminder for defenders: KEV additions are not limited to recently disclosed CVEs. An old, "already fixed" bug can resurface as a live threat the moment adversaries find organizations that never applied the patch.


Recommendations

  1. Identify every BIND installation in your environment — including appliances, embedded network gear, and legacy Linux servers — and check the named version against the affected ranges above.
  2. Upgrade immediately to BIND 9.9.7-P2, BIND 9.10.2-P3, or any later maintained release. There is no configuration-level workaround; ACLs and query restrictions do not block this attack.
  3. Federal agencies subject to CISA Binding Operational Directives must remediate per BOD 22-01 by the October 11, 2026 KEV deadline.
  4. Monitor for unexpected named process restarts or crashes, which can indicate active exploitation attempts even if the service recovers automatically.
  5. Treat this as part of the broader Flax Typhoon advisory — organizations in government, healthcare, critical manufacturing, IT, and education sectors should review the full eight-vulnerability list in the joint FBI/CISA/NSA advisory, not just this single CVE.

Key Takeaways

  1. CVE-2015-5477 is an 11-year-old reachable-assertion denial-of-service flaw in ISC BIND's TKEY query handling, newly added to CISA's KEV catalog on October 8, 2026.
  2. A single crafted DNS query crashes named on both authoritative and recursive servers; ACLs do not mitigate it because the flaw triggers before access-control checks run.
  3. The addition is tied to active exploitation by Flax Typhoon (RedJuliett / Ethereal Panda), the China-linked group behind the Integrity Technology Group stolen-email-access operation disclosed the same week.
  4. Federal agencies face an October 11, 2026 remediation deadline; all organizations running BIND 9.10.2-P2 or earlier (or 9.9.7-P1 or earlier) should patch immediately.
  5. The fix — BIND 9.9.7-P2 / 9.10.2-P3 or later — has existed since 2015. This is a patching-hygiene failure being actively exploited, not a new zero-day.

Sources

CosmicBytez Labs will update this advisory if further detail emerges on the specific exploitation activity tied to this KEV addition.