CVE-2025-13878: Malformed BRID/HHIT records can cause named to terminate unexpectedly
An attacker can cause named to crash by sending a request that results in a corrupt or malicious record.
- Authoritative servers are affected by this vulnerability.
- Resolvers are affected by this vulnerability.
Other sources
Malformed BRID/HHIT records can cause named to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
isc/bindto a version that resolves this vulnerability.Fixed in 9.18.44 - Upgrade
Upgrade
isc/bindto a version that resolves this vulnerability.Fixed in 9.20.18 - Upgrade
Upgrade
isc/bindto a version that resolves this vulnerability.Fixed in 9.21.17 - Upgrade
Upgrade
isc/bindto a version that resolves this vulnerability.Fixed in 9.18.44-S1 - Upgrade
Upgrade
isc/bindto a version that resolves this vulnerability.Fixed in 9.20.18-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13878?
CVE-2025-13878 has a medium severity as it can cause the named service to terminate unexpectedly.
How do I fix CVE-2025-13878?
To resolve CVE-2025-13878, upgrade BIND 9 to a version that is not affected, such as 9.18.44 or 9.20.18.
What versions of BIND 9 are affected by CVE-2025-13878?
CVE-2025-13878 affects BIND 9 versions 9.18.40 to 9.18.43, 9.20.13 to 9.20.17, and 9.21.12 to 9.21.16.
What are the potential impacts of CVE-2025-13878?
The impact of CVE-2025-13878 includes unexpected termination of the named service, potentially disrupting DNS resolution.
Is there a workaround for CVE-2025-13878?
There are no known workarounds for CVE-2025-13878; upgrading to a patched version is the recommended solution.