PT-2026-3771 · Isc · Bind 9
Published
2025-01-01
·
Updated
2026-02-07
·
CVE-2025-13878
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
BIND 9 versions 9.18.40 through 9.18.43
BIND 9 versions 9.20.13 through 9.20.17
BIND 9 versions 9.21.12 through 9.21.16
BIND 9 versions 9.18.40-S1 through 9.18.43-S1
BIND 9 versions 9.20.13-S1 through 9.20.17-S1
Description
Malformed BRID/HHIT records can cause the
named daemon to terminate unexpectedly, leading to a denial-of-service condition. The issue is remotely exploitable without authentication and affects both authoritative name servers and DNS resolvers. The vulnerability allows remote attackers to crash DNS servers by sending specially crafted DNS records. Multiple sources indicate this is a high-severity flaw, with some referring to it as a potential "DNS Doomsday Bug". The vulnerability impacts the named process, which is responsible for handling DNS queries.Recommendations
Upgrade to BIND 9 version 9.18.44
Upgrade to BIND 9 version 9.20.18
Upgrade to BIND 9 version 9.21.17
Fix
LPE
DoS
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bind 9