PT-2026-3771 · Isc · Bind 9

Published

2025-01-01

·

Updated

2026-02-07

·

CVE-2025-13878

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions BIND 9 versions 9.18.40 through 9.18.43 BIND 9 versions 9.20.13 through 9.20.17 BIND 9 versions 9.21.12 through 9.21.16 BIND 9 versions 9.18.40-S1 through 9.18.43-S1 BIND 9 versions 9.20.13-S1 through 9.20.17-S1
Description Malformed BRID/HHIT records can cause the named daemon to terminate unexpectedly, leading to a denial-of-service condition. The issue is remotely exploitable without authentication and affects both authoritative name servers and DNS resolvers. The vulnerability allows remote attackers to crash DNS servers by sending specially crafted DNS records. Multiple sources indicate this is a high-severity flaw, with some referring to it as a potential "DNS Doomsday Bug". The vulnerability impacts the named process, which is responsible for handling DNS queries.
Recommendations Upgrade to BIND 9 version 9.18.44 Upgrade to BIND 9 version 9.20.18 Upgrade to BIND 9 version 9.21.17

Fix

LPE

DoS

Assertion Failure

Weakness Enumeration

Related Identifiers

AZL-75074
CVE-2025-13878
OPENSUSE-SU-2026:10080-1
OPENSUSE-SU-2026:20091-1
RHSA-2026:6935
SUSE-SU-2026:0348-1
SUSE-SU-2026:20135-1

Affected Products

Bind 9