Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-13878

Опубликовано: 21 янв. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Malformed BRID/HHIT records can cause named to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.

A flaw was found in bind. A remote attacker can send a specially crafted request that results in a corrupt or malicious record, causing the 'named' service to crash. This vulnerability leads to a Denial of Service (DoS) for authoritative servers and resolvers.

Отчет

This vulnerability is rated Important for Red Hat products as it affects the BIND DNS server (named). An attacker can cause the named service to crash by sending a specially crafted request, impacting both authoritative and resolver server configurations. This can lead to a denial of service for DNS resolution.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bindNot affected
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindNot affected
Red Hat Enterprise Linux 8bindNot affected
Red Hat Enterprise Linux 8bind9.16Not affected
Red Hat Enterprise Linux 9bindNot affected
Red Hat Enterprise Linux 9bind9.18Not affected
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected
Red Hat Hardened Imagesbind-main-9.18.48-1.hum1FixedRHSA-2026:693507.04.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1286
https://bugzilla.redhat.com/show_bug.cgi?id=2431600bind: bind: Denial of Service via corrupt or malicious record

EPSS

Процентиль: 94%
0.08219
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
7 месяцев назад

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.

CVSS3: 7.5
nvd
7 месяцев назад

Malformed BRID/HHIT records can cause `named` to terminate unexpectedly. This issue affects BIND 9 versions 9.18.40 through 9.18.43, 9.20.13 through 9.20.17, 9.21.12 through 9.21.16, 9.18.40-S1 through 9.18.43-S1, and 9.20.13-S1 through 9.20.17-S1.

CVSS3: 7.5
debian
7 месяцев назад

Malformed BRID/HHIT records can cause `named` to terminate unexpectedl ...

suse-cvrf
7 месяцев назад

Security update for bind

suse-cvrf
7 месяцев назад

Security update for bind

EPSS

Процентиль: 94%
0.08219
Низкий

7.5 High

CVSS3