CVE-2025-8677
published 2025-10-22CVE-2025-8677: Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions…
PriorityP353high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
11.20%
95.5th percentile
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | < bind9 1:9.18.41-1~deb12u1 (bookworm) | bind9 1:9.18.41-1~deb12u1 (bookworm) |
| isc | bind | >= 0 < 9.18.41-r0 | 9.18.41-r0 |
| isc | bind | >= 0 < 9.18.41-r0 | 9.18.41-r0 |
| isc | bind | >= 0 < 9.18.41-r0 | 9.18.41-r0 |
| isc | bind | >= 0 < 9.20.15-r0 | 9.20.15-r0 |
| isc | bind | >= 0 < 9.20.15-r0 | 9.20.15-r0 |
| isc | bind9 | >= 0 < 1:9.16.50-1~deb11u4 | 1:9.16.50-1~deb11u4 |
| isc | bind9 | >= 0 < 1:9.18.41-1~deb12u1 | 1:9.18.41-1~deb12u1 |
| isc | bind9 | >= 0 < 1:9.20.15-1~deb13u1 | 1:9.20.15-1~deb13u1 |
| isc | bind9 | >= 0 < 1:9.20.15-1 | 1:9.20.15-1 |
| isc | bind9 | >= 0 < 1:9.18.39-0ubuntu0.22.04.2 | 1:9.18.39-0ubuntu0.22.04.2 |
| isc | bind9 | >= 0 < 1:9.18.39-0ubuntu0.24.04.2 | 1:9.18.39-0ubuntu0.24.04.2 |
| isc | bind9 | >= 0 < 1:9.20.11-1ubuntu2.1 | 1:9.20.11-1ubuntu2.1 |
| isc | bind9 | >= 0 < 1:9.18.30-0ubuntu0.20.04.2+esm1 | 1:9.18.30-0ubuntu0.20.04.2+esm1 |
| isc | bind_9 | 9.18.0 – 9.18.39 | — |
| isc | bind_9 | 9.18.11-S1 – 9.18.39-S1 | — |
| isc | bind_9 | 9.20.0 – 9.20.13 | — |
| isc | bind_9 | 9.20.9-S1 – 9.20.13-S1 | — |
| isc | bind_9 | 9.21.0 – 9.21.12 | — |
| msrc | azl3_bind_9.20.11-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_bind_9.20.15-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_bind_9.16.50-2_on_cbl_mariner_2.0 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv8.6HIGH
vendor_ubuntu8.6HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
bind9 vulnerabilities
osv·2025-11-12·CVSS 8.6
CVE-2025-8677 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
USN-7836-1 fixed vulnerabilities in Bind. This update provides the
corresponding fixes for Ubuntu 20.04 LTS.
Original advisory details:
Zuyao Xu and Xiang Li discovered that Bind incorrectly handled certain
malformed DNSKEY records. A remote attacker could possibly use this issue
to cause Bind to consume resources, resulting in a denial of service.
(CVE-2025-8677)
Yuxiao Wu, Yunyi Zhang, Baojun Liu, and Haixin Duan discovered that Bind
incorrectly accepted certain records from answers. A remote attacker could
possibly use this issue to perform a cache poisoning attack.
(CVE-2025-40778)
Amit Klein and Omer Ben Simhon discovered that Bind used a weak PRNG. A
remote attacker could possibly use this issue to perform a cache poisoning
attack. (CVE-2025-40780)
OSV
CVE-2025-8677: Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion
osv·2025-10-22·CVSS 7.5
CVE-2025-8677 [HIGH] CVE-2025-8677: Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
GHSA
GHSA-924g-f9mr-cm6x: Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion
ghsa_unreviewed·2025-10-22
CVE-2025-8677 [HIGH] CWE-405 GHSA-924g-f9mr-cm6x: Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
OSV
bind9 vulnerabilities
osv·2025-10-22·CVSS 8.6
CVE-2025-8677 [HIGH] bind9 vulnerabilities
bind9 vulnerabilities
Zuyao Xu and Xiang Li discovered that Bind incorrectly handled certain
malformed DNSKEY records. A remote attacker could possibly use this issue
to cause Bind to consume resources, resulting in a denial of service.
(CVE-2025-8677)
Yuxiao Wu, Yunyi Zhang, Baojun Liu, and Haixin Duan discovered that Bind
incorrectly accepted certain records from answers. A remote attacker could
possibly use this issue to perform a cache poisoning attack.
(CVE-2025-40778)
Amit Klein and Omer Ben Simhon discovered that Bind used a weak PRNG. A
remote attacker could possibly use this issue to perform a cache poisoning
attack. (CVE-2025-40780)
OSV
CVE-2025-8677: Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion
osv·2025-10-22·CVSS 7.5
CVE-2025-8677 [HIGH] CVE-2025-8677: Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2025-11-12·CVSS 8.6
CVE-2025-40780 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
USN-7836-1 fixed vulnerabilities in Bind. This update provides the
corresponding fixes for Ubuntu 20.04 LTS.
Original advisory details:
Zuyao Xu and Xiang Li discovered that Bind incorrectly handled certain
malformed DNSKEY records. A remote attacker could possibly use this issue
to cause Bind to consume resources, resulting in a denial of service.
(CVE-2025-8677)
Yuxiao Wu, Yunyi Zhang, Baojun Liu, and Haixin Duan discovered that Bind
incorrectly accepted certain records from answers. A remote attacker could
possibly use this issue to perform a cache poisoning attack.
(CVE-2025-40778)
Amit Klein and Omer Ben Simhon discovered that Bind used a weak PRNG. A
remote attacker could possibly use this issue to
Red Hat
bind: Resource exhaustion via malformed DNSKEY handling
vendor_redhat·2025-10-22·CVSS 7.5
CVE-2025-8677 [HIGH] CWE-400 bind: Resource exhaustion via malformed DNSKEY handling
bind: Resource exhaustion via malformed DNSKEY handling
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
A vulnerability was found in BIND 9 resolvers, where processing malformed DNSKEY records from a specially crafted zone can lead to resource exhaustion, primarily causing excessive CPU utilization. This issue enables a remote, unauthenticated attacker to degrade resolver performance and potentially cause a denial of service (DoS) for legitimate DNS clients.
Statement: This vulnerability is considered Important because it allows a remote, una
Ubuntu
Bind vulnerabilities
vendor_ubuntu·2025-10-22·CVSS 8.6
CVE-2025-40778 [HIGH] Bind vulnerabilities
Title: Bind vulnerabilities
Summary: Several security issues were fixed in Bind.
Zuyao Xu and Xiang Li discovered that Bind incorrectly handled certain
malformed DNSKEY records. A remote attacker could possibly use this issue
to cause Bind to consume resources, resulting in a denial of service.
(CVE-2025-8677)
Yuxiao Wu, Yunyi Zhang, Baojun Liu, and Haixin Duan discovered that Bind
incorrectly accepted certain records from answers. A remote attacker could
possibly use this issue to perform a cache poisoning attack.
(CVE-2025-40778)
Amit Klein and Omer Ben Simhon discovered that Bind used a weak PRNG. A
remote attacker could possibly use this issue to perform a cache poisoning
attack. (CVE-2025-40780)
Instructions: In general, a standard system update will make all the necessary change
Microsoft
Resource exhaustion via malformed DNSKEY handling
vendor_msrc·2025-10-14·CVSS 7.5
CVE-2025-8677 [HIGH] CWE-405 Resource exhaustion via malformed DNSKEY handling
Resource exhaustion via malformed DNSKEY handling
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
isc: isc
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft
Debian
CVE-2025-8677: bind9 - Querying for records within a specially crafted zone containing certain malforme...
vendor_debian·2025·CVSS 7.5
CVE-2025-8677 [HIGH] CVE-2025-8677: bind9 - Querying for records within a specially crafted zone containing certain malforme...
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion. This issue affects BIND 9 versions 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
Scope: local
bookworm: resolved (fixed in 1:9.18.41-1~deb12u1)
bullseye: resolved (fixed in 1:9.16.50-1~deb11u4)
forky: resolved (fixed in 1:9.20.15-1)
sid: resolved (fixed in 1:9.20.15-1)
trixie: resolved (fixed in 1:9.20.15-1~deb13u1)
No detection rules found.
No public exploits indexed.
2025-10-22
Published