CVE-2025-13878: high-severity vulnerability in ISC BIND 9
Malformed BRID/HHIT records can cause named to terminate unexpectedly
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 9.2%
exploitation probability
9.2%top 5% of all CVEs
observed exploitation
nono source reports it
Malformed BRID/HHIT records can cause `named` to terminate unexpectedly.
This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
ISC · BIND 9Related CVEs — ISC BIND 9
In the same product, most dangerous first.
CVE-2018-5740HIGHA flaw in the "deny-answer-aliases" feature can cause an assertion failure in namedEPSS 59.6%CVE-2022-3736HIGHnamed configured to answer from stale cache may terminate unexpectedly while processing RRSIG queriesEPSS 48.7%CVE-2017-3145HIGHImproper fetch cleanup sequencing in the resolver can cause named to crashEPSS 27.9%CVE-2022-3488HIGHnamed may terminate unexpectedly when processing ECS options in repeated responses to iterative queriesEPSS 19.2%CVE-2024-12705HIGHDNS-over-HTTPS implementation suffers from multiple issues under heavy query loadEPSS 18.4%CVE-2017-3143HIGHAn error in TSIG authentication can permit unauthorized dynamic updatesEPSS 18.3%
References
https://access.redhat.com/errata/RHSA-2026:6935https://access.redhat.com/security/cve/CVE-2025-13878https://bugzilla.redhat.com/show_bug.cgi?id=2431600https://downloads.isc.org/isc/bind9/9.18.44https://downloads.isc.org/isc/bind9/9.20.18https://downloads.isc.org/isc/bind9/9.21.17https://kb.isc.org/docs/cve-2025-13878https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13878.jsonhttp://www.openwall.com/lists/oss-security/2026/01/21/3