ISC BIND Vulnerability (CVE‑2015‑5477) Allows Remote Denial‑of‑Service via TKEY Queries
A data‑processing error in ISC BIND can be triggered by malicious TKEY queries, causing the DNS service to crash. The issue highlights the need for continuous patch management and auditable evidence of service‑availability controls.
ADTP Breach Watch· October 8, 2026· CISA KEV
SeverityMedium
Type🐛 Vulnerability
ConfidenceHigh
ReportedOct 8, 2026
Other / UnknownTechnology & SaaS providers that run ISC BIND for internal or customer‑facing DNS.Vulnerability Exploit
What happened
ISC BIND versions prior to the 2015 patch contain a flaw that lets an unauthenticated attacker send specially‑crafted TKEY queries, leading to a denial‑of‑service condition on the DNS server.
Why it matters for trust and compliance
The incident tests the control objective of incident response and service continuity—organizations must prove they can detect, remediate, and document availability‑impacting flaws.
Patch‑management evidence satisfies availability‑related controls across multiple frameworks.
Logging and alerting on abnormal DNS traffic provides continuous assurance of service health.
Who is affected
Technology & SaaS providers that run ISC BIND for internal or customer‑facing DNS.
Recommended actions
Apply the ISC‑issued patch or upgrade to the latest BIND version.
Enable detailed DNS query logging and set alerts for abnormal TKEY activity.
Document the remediation steps in your change‑management system for audit readiness.
Details
Organizations
ISC
CVEs
CVE-2015-5477
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.