CVE-2025-8677: Resource exhaustion via malformed DNSKEY handling
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
Other sources
Resource exhaustion via malformed DNSKEY handling
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.18.41 - Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.20.15 - Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.21.14 - Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.18.41-S1 - Upgrade
Upgrade
ISC BIND 9to a version that resolves this vulnerability.Fixed in 9.20.15-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8677?
CVE-2025-8677 has been rated as a high severity vulnerability due to its potential to cause CPU exhaustion in affected BIND 9 versions.
How do I fix CVE-2025-8677?
To mitigate CVE-2025-8677, upgrade to a non-affected version of BIND 9 that is not within the specified vulnerable ranges.
Which versions are affected by CVE-2025-8677?
CVE-2025-8677 affects ISC BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, and 9.21.0 through 9.21.12 among others.
What is the impact of CVE-2025-8677 on my DNS server?
The impact of CVE-2025-8677 is that querying specially crafted malformed DNSKEY records can lead to significant CPU exhaustion on your DNS server.
Is CVE-2025-8677 being actively exploited in the wild?
As of now, there are no reported cases of CVE-2025-8677 being actively exploited, but it is advisable to patch affected systems promptly.