cbcvebase.
CVE-2015-5722
published 2015-09-05

CVE-2015-5722: buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and…

PriorityP348high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
33.65%
98.2th percentile
buffer.c in named in ISC BIND 9.x before 9.9.7-P3 and 9.10.x before 9.10.2-P4 allows remote attackers to cause a denial of service (assertion failure and daemon exit) by creating a zone containing a malformed DNSSEC key and issuing a query for a name in that zone.

Affected

9 ranges
VendorProductVersion rangeFixed in
applemac_os_x_server
appleos_x_server
debianbind9< bind9 1:9.9.5.dfsg-12 (bookworm)bind9 1:9.9.5.dfsg-12 (bookworm)
iscbind<= 9.9.7
iscbind<= 9.10.2
iscbind9>= 0 < 1:9.9.5.dfsg-121:9.9.5.dfsg-12
iscbind9>= 0 < 1:9.9.5.dfsg-121:9.9.5.dfsg-12
iscbind9>= 0 < 1:9.9.5.dfsg-121:9.9.5.dfsg-12
iscbind9>= 0 < 1:9.9.5.dfsg-121:9.9.5.dfsg-12

Detection & IOCsextracted from sources · hover to see the quote

  • Target the assertion failure in buffer.c within named (ISC BIND). A remote attacker triggers a crash by sending a DNS query that requires a response from a zone containing a malformed DNSSEC key, causing a failed assertion and daemon exit.
  • Recursive resolvers performing DNSSEC validation are at greatest risk; monitor for unexpected named process crashes (assertion failures) especially when querying zones with DNSSEC keys.
  • Affected BIND versions: 9.0.0 through 9.8.8, 9.9.0 through 9.9.7-P2, and 9.10.0 through 9.10.2-P3. Use version detection to identify vulnerable named instances.
  • ·No workaround is available for vulnerable BIND versions; the only mitigation is patching to 9.9.7-P3 or 9.10.2-P4 (or later).
  • ·Both validating resolvers (recursive) and authoritative servers can be affected if an attacker controls a zone the server must query, broadening the attack surface beyond just recursive resolvers.

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.