PT-2025-43379 · Isc+10 · Bind+10
CVE-2025-8677
·
Published
2025-10-22
·
Updated
2026-05-19
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
BIND versions 9.18.0 through 9.18.39
BIND versions 9.20.0 through 9.20.13
BIND versions 9.21.0 through 9.21.12
BIND versions 9.18.11-S1 through 9.18.39-S1
BIND versions 9.20.9-S1 through 9.20.13-S1
Description
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
Recommendations
Update BIND to a version later than 9.18.39.
Update BIND to a version later than 9.20.13.
Update BIND to a version later than 9.21.12.
Update BIND to a version later than 9.18.39-S1.
Update BIND to a version later than 9.20.13-S1.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Bind
Centos
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu