Executive brief
A vulnerability in BIND 9, a widely used system for translating domain names into IP addresses, allows a remote attacker to crash the service. By sending a specially crafted DNS request containing malformed records, an attacker can cause the 'named' process to terminate unexpectedly. This results in a denial-of-service (DoS) condition, preventing users and systems from resolving website addresses and other network services. Both authoritative DNS servers and recursive resolvers are affected.
Technical details
A reachable assertion vulnerability (CWE-617) exists in BIND 9 due to improper validation of malformed BRID and HHIT resource records. An unauthenticated remote attacker can trigger this vulnerability by sending a DNS query that results in the processing of a corrupt or malicious record. This causes the 'named' process to crash, affecting both authoritative servers and resolvers. The issue is fixed in BIND versions 9.18.44, 9.20.18, and 9.21.17. No workarounds are currently known.
Affected products
- ISC BIND 9 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16
- ISC BIND 9 Supported Preview Edition 9.18.40-S1 through 9.18.43-S1, 9.20.13-S1 through 9.20.17-S1
Timeline
- 2026-01-14: other: Early notification provided by ISC
- 2026-01-21: advisory: Public disclosure by ISC
- 2026-01-21: patched: Patched versions 9.18.44, 9.20.18, and 9.21.17 released
References
- https://downloads.isc.org/isc/bind9/9.18.44
- https://downloads.isc.org/isc/bind9/9.20.18
- https://downloads.isc.org/isc/bind9/9.21.17
- https://kb.isc.org/docs/cve-2025-13878
- http://www.openwall.com/lists/oss-security/2026/01/21/3
- https://access.redhat.com/errata/RHSA-2026:6935
- https://access.redhat.com/security/cve/CVE-2025-13878