VORANT. Threat Intelligence Sign in Get the full feed

BIND 9 DoS flaw patched by ISC

medium vulnerability

ISC patched CVE-2025-13878, a denial-of-service vulnerability in BIND 9 that could allow remote attackers to crash DNS servers; no active exploitation observed.

The Internet Systems Consortium (ISC) disclosed and patched a denial-of-service vulnerability (CVE-2025-13878) affecting BIND 9, the widely-deployed DNS server software. The flaw allows a remote unauthenticated attacker to trigger abnormal termination of the DNS service. Japan's Information-technology Promotion Agency (IPA) issued an advisory noting that while no active exploitation has been observed, attacks may emerge and DNS administrators should upgrade promptly.

ISC released patched versions across multiple branches: BIND 9.18.44, 9.20.18, 9.21.17, and the Supported Preview Edition variants 9.18.44-S1 and 9.20.18-S1. Organizations running BIND 9 should apply the relevant update to mitigate the risk of service disruption.

The advisory emphasizes the standard patch-now guidance for DNS infrastructure vulnerabilities, recognizing that exploitation tooling may follow disclosure. No additional technical details on the attack vector or proof-of-concept code were provided in the public notice.

Mentioned in this report

Vulnerabilities CVE-2025-13878

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20260123.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free