# BIND 9 DoS flaw patched by ISC

Published: 2025-05-22 · Severity: medium
Canonical: https://vorant.io/reports/ed750889-8bb0-5b62-8c8d-7d0480299f89/bind-9-dos-flaw-patched-by-isc

> ISC disclosed CVE-2025-40775, a denial-of-service vulnerability in BIND 9 that allows remote attackers to crash DNS servers; patches released, no exploitation observed yet.

The Internet Systems Consortium (ISC) has published details of CVE-2025-40775, a denial-of-service vulnerability affecting BIND 9 DNS server software. The flaw permits a remote, unauthenticated attacker to trigger abnormal termination of the DNS server process. While no active exploitation has been observed, ISC and Japan's IPA cybersecurity center warn that attacks may emerge and recommend immediate patching.

The vulnerability affects BIND 9.18.0 and later versions; earlier branches were not evaluated in this advisory. ISC has released patches in BIND 9.20.9 and 9.21.8. DNS server administrators are urged to upgrade to these versions to mitigate the risk.

This is a standard patch advisory with no active in-the-wild activity reported. Organizations running BIND 9 should prioritize the update during their next maintenance window, as DNS infrastructure remains a high-value target for disruption.

## Mentioned in this report

- Vulnerabilities: CVE-2025-40775

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20250523.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ed750889-8bb0-5b62-8c8d-7d0480299f89/bind-9-dos-flaw-patched-by-isc.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
