logo

BIND 9 Flaw Lets Attackers Crash Servers With Malicious DNS Records

ID: f2274e63-c5ff-524c-a33a-a4888ca62c17

STIX ID: report--f2274e63-c5ff-524c-a33a-a4888ca62c17

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-01-22

Date Updated: 2026-04-22

Author: Varshini

...
...

A critical BIND 9 vulnerability (CVE-2025-13878) allows remote unauthenticated attackers to crash the named process by sending malformed BRID or HHIT DNS records, causing a denial-of-service; ISC rated it CVSS 7.5 (High), published patched versions for affected 9.18/9.20/9.21 branches, and provided IoCs, detection rules, and mitigation guidance (patching, RRL, rate-limiting).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.