CVE-2025-8677: fallo de gravedad alta en ISC BIND 9
Resource exhaustion via malformed DNSKEY handling
Publicada el · Actualizada el
26Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.5epss 11%
probabilidad de explotación
11%top 4% de las CVE
explotación observada
noninguna fuente lo reporta
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Productos afectados
ISC · BIND 9CVEs relacionadas — ISC BIND 9
En el mismo producto, de las más peligrosas a las menos.
CVE-2018-5740HIGHA flaw in the "deny-answer-aliases" feature can cause an assertion failure in namedEPSS 59.6%CVE-2022-3736HIGHnamed configured to answer from stale cache may terminate unexpectedly while processing RRSIG queriesEPSS 48.7%CVE-2017-3145HIGHImproper fetch cleanup sequencing in the resolver can cause named to crashEPSS 27.9%CVE-2022-3488HIGHnamed may terminate unexpectedly when processing ECS options in repeated responses to iterative queriesEPSS 19.2%CVE-2024-12705HIGHDNS-over-HTTPS implementation suffers from multiple issues under heavy query loadEPSS 18.4%CVE-2017-3143HIGHAn error in TSIG authentication can permit unauthorized dynamic updatesEPSS 18.3%