CVE-2025-13878

7.5

ISC · BIND 9

A vulnerability in ISC BIND 9 allows unauthenticated remote attackers to cause a denial of service via malformed BRID or HHIT records, triggering an unexpected termination of the named process.

Executive summary

A critical denial of service vulnerability in ISC BIND 9 can be triggered by unauthenticated remote attackers, leading to the unexpected termination of the DNS service.

Vulnerability

The flaw is a reachable assertion (CWE-617) triggered by the processing of malformed BRID or HHIT records. An unauthenticated remote attacker can exploit this to crash the named service, resulting in a denial of service for all dependent network infrastructure.

Business impact

Successful exploitation of this vulnerability results in a complete loss of DNS resolution for the affected server, which can cause widespread service outages across an organization. Given the CVSS score of 7.5, this high severity vulnerability represents a significant risk to network availability and business continuity.

Remediation

Immediate Action: Upgrade to the patched release corresponding to your current deployment: BIND 9.18.44, 9.20.18, 9.21.17, 9.18.44-S1, or 9.20.18-S1.

Proactive Monitoring: Monitor system logs for repeated process restarts of the named service, which may indicate attempted exploitation or recurring crashes.

Compensating Controls: Implement network boundary protections, such as Access Control Lists (ACLs) or firewalls, to restrict DNS queries to known, trusted sources where feasible.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations running the affected versions of BIND 9 must prioritize patching to the latest stable release. Because this vulnerability allows for remote service disruption without the need for credentials, the risk of automated exploitation is high. Plan for an immediate deployment of the referenced security updates to ensure network stability.

More ISC CVEs

Sources

Originally found and disclosed by ISC would like to thank Vlatko Kosturjak from Marlink Cyber for bringing this vulnerability to our attention., per the CVE Program record.