CVE-2025-8677
7.5ISC · BIND 9
A vulnerability in ISC BIND 9 allows unauthenticated remote attackers to cause CPU exhaustion by querying for records within a specially crafted zone containing malformed DNSKEY records.
Executive summary
A high-severity denial of service vulnerability in ISC BIND 9 allows unauthenticated attackers to exhaust system CPU resources via malicious DNS queries.
Vulnerability
This is an asymmetric resource consumption vulnerability (CWE-405) that triggers excessive CPU usage when the service processes malformed DNSKEY records. The attack is unauthenticated and can be triggered remotely by any user capable of sending DNS queries to the affected server.
Business impact
Successful exploitation of this flaw results in a denial of service condition, potentially rendering the DNS infrastructure unresponsive. Given the CVSS score of 7.5, this high-severity vulnerability poses a significant risk to network availability and business continuity for organizations relying on BIND 9 for critical name resolution services.
Remediation
Immediate Action: Upgrade to the patched release corresponding to your current deployment: BIND 9.18.41, 9.20.15, 9.21.14, 9.18.41-S1, or 9.20.15-S1.
Proactive Monitoring: Monitor server CPU utilization and DNS query logs for spikes or patterns of anomalous requests targeting specific zones.
Compensating Controls: Implement rate limiting on DNS queries at the network perimeter to mitigate the impact of high-volume malicious traffic while patches are pending.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The risk posed by this denial of service vulnerability is substantial, particularly for public-facing DNS resolvers. Administrators should prioritize the deployment of the provided security updates immediately to protect against potential service outages and ensure the ongoing stability of their DNS infrastructure.
More ISC CVEs
Sources
Originally found and disclosed by ISC would like to thank Zuyao Xu and Xiang Li from the All-in-One Security and Privacy Laboratory at Nankai University f, per the CVE Program record.
- CVE-2025-8677 Vendor advisory