BIND 9 DoS flaw patched by ISC
ISC disclosed CVE-2025-40775, a denial-of-service vulnerability in BIND 9 that allows remote attackers to crash DNS servers; patches released, no exploitation observed yet.
The Internet Systems Consortium (ISC) has published details of CVE-2025-40775, a denial-of-service vulnerability affecting BIND 9 DNS server software. The flaw permits a remote, unauthenticated attacker to trigger abnormal termination of the DNS server process. While no active exploitation has been observed, ISC and Japan's IPA cybersecurity center warn that attacks may emerge and recommend immediate patching.
The vulnerability affects BIND 9.18.0 and later versions; earlier branches were not evaluated in this advisory. ISC has released patches in BIND 9.20.9 and 9.21.8. DNS server administrators are urged to upgrade to these versions to mitigate the risk.
This is a standard patch advisory with no active in-the-wild activity reported. Organizations running BIND 9 should prioritize the update during their next maintenance window, as DNS infrastructure remains a high-value target for disruption.
Mentioned in this report
Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20250523.html
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free