{"api_version":"1","generated_at":"2026-07-23T15:00:54+00:00","cve":"CVE-2025-13878","urls":{"html":"https://cve.report/CVE-2025-13878","api":"https://cve.report/api/cve/CVE-2025-13878.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2025-13878","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2025-13878"},"summary":{"title":"Malformed BRID/HHIT records can cause named to terminate unexpectedly","description":"Malformed BRID/HHIT records can cause `named` to terminate unexpectedly.\nThis issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.","state":"PUBLISHED","assigner":"isc","published_at":"2026-01-21 15:16:05","updated_at":"2026-07-15 02:17:16"},"problem_types":["CWE-617","CWE-1286","CWE-617 CWE-617 Reachable Assertion","CWE-1286 Improper Validation of Syntactic Correctness of Input"],"metrics":[{"version":"3.1","source":"ADP","type":"CVSS","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}},{"version":"3.1","source":"security-officer@isc.org","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.5","severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","data":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"references":[{"url":"https://downloads.isc.org/isc/bind9/9.21.17","name":"https://downloads.isc.org/isc/bind9/9.21.17","refsource":"security-officer@isc.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2431600","name":"https://bugzilla.redhat.com/show_bug.cgi?id=2431600","refsource":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"http://www.openwall.com/lists/oss-security/2026/01/21/3","name":"http://www.openwall.com/lists/oss-security/2026/01/21/3","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://downloads.isc.org/isc/bind9/9.20.18","name":"https://downloads.isc.org/isc/bind9/9.20.18","refsource":"security-officer@isc.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://kb.isc.org/docs/cve-2025-13878","name":"https://kb.isc.org/docs/cve-2025-13878","refsource":"security-officer@isc.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/errata/RHSA-2026:6935","name":"https://access.redhat.com/errata/RHSA-2026:6935","refsource":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://downloads.isc.org/isc/bind9/9.18.44","name":"https://downloads.isc.org/isc/bind9/9.18.44","refsource":"security-officer@isc.org","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13878.json","name":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13878.json","refsource":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://access.redhat.com/security/cve/CVE-2025-13878","name":"https://access.redhat.com/security/cve/CVE-2025-13878","refsource":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-13878","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-13878","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"ISC","product":"BIND 9","version":"affected 9.18.40 9.18.43 custom","platforms":[]},{"source":"CNA","vendor":"ISC","product":"BIND 9","version":"affected 9.20.13 9.20.17 custom","platforms":[]},{"source":"CNA","vendor":"ISC","product":"BIND 9","version":"affected 9.21.12 9.21.16 custom","platforms":[]},{"source":"CNA","vendor":"ISC","product":"BIND 9","version":"affected 9.18.40-S1 9.18.43-S1 custom","platforms":[]},{"source":"CNA","vendor":"ISC","product":"BIND 9","version":"affected 9.20.13-S1 9.20.17-S1 custom","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Hardened Images","version":"unaffected 9.18.48-1.hum1 * rpm","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 10","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 6","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 7","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 8","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat Enterprise Linux 9","version":"","platforms":[]},{"source":"ADP","vendor":"Red Hat","product":"Red Hat OpenShift Container Platform 4","version":"","platforms":[]}],"timeline":[{"source":"ADP","time":"2026-01-21T13:45:49.972Z","lang":"en","value":"Reported to Red Hat."},{"source":"ADP","time":"2026-01-21T00:00:00.000Z","lang":"en","value":"Made public."}],"solutions":[{"source":"CNA","title":"","value":"Upgrade to the patched release most closely related to your current version of BIND 9: 9.18.44, 9.20.18, 9.21.17, 9.18.44-S1, or 9.20.18-S1.","time":"","lang":"en"},{"source":"ADP","title":"","value":"RHSA-2026:6935: Red Hat Hardened Images","time":"","lang":"en"}],"workarounds":[{"source":"CNA","title":"","value":"No workarounds known.","time":"","lang":"en"},{"source":"ADP","title":"","value":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.","time":"","lang":"en"}],"exploits":[{"source":"CNA","title":"","value":"We are not aware of any active exploits.","time":"","lang":"en"}],"credits":[{"source":"CNA","value":"ISC would like to thank Vlatko Kosturjak from Marlink Cyber for bringing this vulnerability to our attention.","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2025","cve_id":"13878","cve":"CVE-2025-13878","epss":"0.082190000","percentile":"0.942530000","score_date":"2026-07-17","updated_at":"2026-07-18 00:07:22"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2025-13878","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-01-21T14:57:50.807267Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-01-21T14:58:14.618Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"},{"providerMetadata":{"dateUpdated":"2026-01-21T18:13:38.157Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"url":"http://www.openwall.com/lists/oss-security/2026/01/21/3"}],"title":"CVE Program Container"},{"affected":[{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:hummingbird:1"],"defaultStatus":"affected","packageName":"bind-main","product":"Red Hat Hardened Images","vendor":"Red Hat","versions":[{"lessThan":"*","status":"unaffected","version":"9.18.48-1.hum1","versionType":"rpm"}]},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:10"],"defaultStatus":"unaffected","packageName":"bind","product":"Red Hat Enterprise Linux 10","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:6"],"defaultStatus":"unaffected","packageName":"bind","product":"Red Hat Enterprise Linux 6","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:7"],"defaultStatus":"unaffected","packageName":"bind","product":"Red Hat Enterprise Linux 7","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"unaffected","packageName":"bind","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:8"],"defaultStatus":"unaffected","packageName":"bind9.16","product":"Red Hat Enterprise Linux 8","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"unaffected","packageName":"bind","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"unaffected","packageName":"bind9.18","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/o:redhat:enterprise_linux:9"],"defaultStatus":"unaffected","packageName":"dhcp","product":"Red Hat Enterprise Linux 9","vendor":"Red Hat"},{"collectionURL":"https://access.redhat.com/downloads/content/package-browser/","cpes":["cpe:/a:redhat:openshift:4"],"defaultStatus":"unaffected","packageName":"rhcos","product":"Red Hat OpenShift Container Platform 4","vendor":"Red Hat"}],"datePublic":"2026-01-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"A flaw was found in bind. A remote attacker can send a specially crafted request that results in a corrupt or malicious record, causing the 'named' service to crash. This vulnerability leads to a Denial of Service (DoS) for authoritative servers and resolvers."}],"metrics":[{"other":{"content":{"namespace":"https://access.redhat.com/security/updates/classification/","value":"Important"},"type":"Red Hat severity rating"}},{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"},"format":"CVSS"}],"problemTypes":[{"descriptions":[{"cweId":"CWE-1286","description":"Improper Validation of Syntactic Correctness of Input","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-07-15T01:27:25.559Z","orgId":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","shortName":"redhat-SADP"},"references":[{"tags":["vdb-entry","x_refsource_REDHAT"],"url":"https://access.redhat.com/security/cve/CVE-2025-13878"},{"name":"RHBZ#2431600","tags":["issue-tracking","x_refsource_REDHAT"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2431600"},{"tags":["x_sadp-csaf-vex"],"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13878.json"},{"tags":["vendor-advisory","x_refsource_REDHAT"],"url":"https://access.redhat.com/errata/RHSA-2026:6935"}],"solutions":[{"lang":"en","value":"RHSA-2026:6935: Red Hat Hardened Images"}],"timeline":[{"lang":"en","time":"2026-01-21T13:45:49.972Z","value":"Reported to Red Hat."},{"lang":"en","time":"2026-01-21T00:00:00.000Z","value":"Made public."}],"title":"bind: bind: Denial of Service via corrupt or malicious record","workarounds":[{"lang":"en","value":"Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability."}],"x_adpType":"supplier","x_generator":{"engine":"sadp-cli 1.0.0"}}],"cna":{"affected":[{"defaultStatus":"unaffected","product":"BIND 9","vendor":"ISC","versions":[{"lessThanOrEqual":"9.18.43","status":"affected","version":"9.18.40","versionType":"custom"},{"lessThanOrEqual":"9.20.17","status":"affected","version":"9.20.13","versionType":"custom"},{"lessThanOrEqual":"9.21.16","status":"affected","version":"9.21.12","versionType":"custom"},{"lessThanOrEqual":"9.18.43-S1","status":"affected","version":"9.18.40-S1","versionType":"custom"},{"lessThanOrEqual":"9.20.17-S1","status":"affected","version":"9.20.13-S1","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*","versionEndIncluding":"9.18.43","versionStartIncluding":"9.18.40","vulnerable":true},{"criteria":"cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*","versionEndIncluding":"9.20.17","versionStartIncluding":"9.20.13","vulnerable":true},{"criteria":"cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*","versionEndIncluding":"9.21.16","versionStartIncluding":"9.21.12","vulnerable":true},{"criteria":"cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*","versionEndIncluding":"9.18.43-S1","versionStartIncluding":"9.18.40-S1","vulnerable":true},{"criteria":"cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*","versionEndIncluding":"9.20.17-S1","versionStartIncluding":"9.20.13-S1","vulnerable":true}],"operator":"OR"}]}],"credits":[{"lang":"en","value":"ISC would like to thank Vlatko Kosturjak from Marlink Cyber for bringing this vulnerability to our attention."}],"datePublic":"2026-01-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Malformed BRID/HHIT records can cause `named` to terminate unexpectedly.\nThis issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1."}],"exploits":[{"lang":"en","value":"We are not aware of any active exploits."}],"impacts":[{"descriptions":[{"lang":"en","value":"An attacker can cause `named` to crash by sending a request that results in a corrupt or malicious record."}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","version":"3.1"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-617","description":"CWE-617 Reachable Assertion","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-01-21T14:43:27.260Z","orgId":"404fd4d2-a609-4245-b543-2c944a302a22","shortName":"isc"},"references":[{"name":"CVE-2025-13878","tags":["vendor-advisory"],"url":"https://kb.isc.org/docs/cve-2025-13878"},{"tags":["patch"],"url":"https://downloads.isc.org/isc/bind9/9.18.44"},{"tags":["patch"],"url":"https://downloads.isc.org/isc/bind9/9.20.18"},{"tags":["patch"],"url":"https://downloads.isc.org/isc/bind9/9.21.17"}],"solutions":[{"lang":"en","value":"Upgrade to the patched release most closely related to your current version of BIND 9: 9.18.44, 9.20.18, 9.21.17, 9.18.44-S1, or 9.20.18-S1."}],"source":{"discovery":"EXTERNAL"},"title":"Malformed BRID/HHIT records can cause named to terminate unexpectedly","workarounds":[{"lang":"en","value":"No workarounds known."}],"x_generator":{"engine":"cvelib 1.8.0"}}},"cveMetadata":{"assignerOrgId":"404fd4d2-a609-4245-b543-2c944a302a22","assignerShortName":"isc","cveId":"CVE-2025-13878","datePublished":"2026-01-21T14:43:27.260Z","dateReserved":"2025-12-02T11:08:04.266Z","dateUpdated":"2026-07-15T01:27:25.559Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-01-21 15:16:05","lastModifiedDate":"2026-07-15 02:17:16","problem_types":["CWE-617","CWE-1286","CWE-617 CWE-617 Reachable Assertion","CWE-1286 Improper Validation of Syntactic Correctness of Input"],"metrics":{"cvssMetricV31":[{"source":"security-officer@isc.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6},{"source":"0b0ca135-0b70-47e7-9f44-1890c2a1c46c","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-21T14:57:50.807267Z","id":"CVE-2025-13878","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2025","CveId":"13878","Ordinal":"1","Title":"Malformed BRID/HHIT records can cause named to terminate unexpec","CVE":"CVE-2025-13878","Year":"2025"},"notes":[{"CveYear":"2025","CveId":"13878","Ordinal":"1","NoteData":"Malformed BRID/HHIT records can cause `named` to terminate unexpectedly.\nThis issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.","Type":"Description","Title":"Malformed BRID/HHIT records can cause named to terminate unexpec"}]}}}