VORANT. Threat Intelligence Sign in Get the full feed

BIND 9 DoS Flaw Prompts IPA Patch Advisory

medium vulnerability infrastructuretechnology

IPA warns of a denial-of-service vulnerability in ISC BIND 9 that could crash DNS servers, urging admins to upgrade to patched versions.

The Information-technology Promotion Agency (IPA) of Japan has issued an advisory regarding a denial-of-service vulnerability (CVE-2025-13878) in ISC BIND 9, a widely used DNS server software. If exploited, a remote attacker could cause the affected DNS server to abnormally terminate, potentially disrupting DNS resolution services.

No active exploitation has been observed at this time, but IPA cautions that attacks could emerge in the future given the public disclosure of the flaw. DNS server administrators are advised to upgrade to the patched versions released by ISC: BIND 9.18.44, 9.20.18, 9.21.17, and the Supported Preview Edition releases 9.18.44-S1 and 9.20.18-S1.

Given BIND's broad deployment as core internet infrastructure, unpatched instances represent an availability risk to organizations relying on it for DNS resolution. This is a standard patch advisory with no confirmed in-the-wild exploitation, warranting timely but not emergency remediation.

Mentioned in this report

Vulnerabilities CVE-2025-13878

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20260123.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free