# BIND 9 DoS Flaw Prompts Patch Advisory

Published: 2025-05-22 · Severity: medium · Sectors: telecommunications, infrastructure
Canonical: https://vorant.io/reports/ed750889-8bb0-5b62-8c8d-7d0480299f89/bind-9-dos-flaw-prompts-patch-advisory

> IPA warns of a denial-of-service vulnerability in ISC BIND 9 that could crash DNS servers, urging admins to upgrade to fixed versions.

The Information-technology Promotion Agency (IPA) of Japan issued an advisory regarding a denial-of-service vulnerability, CVE-2025-40775, affecting ISC BIND 9 DNS server software. If exploited, a remote attacker could cause the affected product to terminate abnormally, disrupting DNS resolution services.

No active exploitation has been observed at the time of publication, but the IPA cautions that attacks could emerge in the future and recommends that DNS server administrators apply patches promptly. ISC has released fixed versions BIND 9.20.9 and BIND 9.21.8 to address the flaw; versions prior to 9.18.0 were not evaluated for this vulnerability.

## Mentioned in this report

- Vulnerabilities: CVE-2025-40775

Source reporting: https://www.ipa.go.jp/security/security-alert/2025/alert20250523.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ed750889-8bb0-5b62-8c8d-7d0480299f89/bind-9-dos-flaw-prompts-patch-advisory.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
