
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-13878 is a denial-of-service vulnerability in ISC BIND 9 where malformed BRID/HHIT DNS records can cause the named daemon to terminate unexpectedly due to a reachable assertion failure. Disclosed on January 21, 2026, by Internet Systems Consortium (ISC), it affects BIND 9 versions 9.18.40–9.18.43, 9.20.13–9.20.17, 9.21.12–9.21.16, and the corresponding Subscription Edition variants 9.18.40-S1–9.18.43-S1 and 9.20.13-S1–9.20.17-S1. The vulnerability was discovered and reported by Marlink Cyber. It carries a CVSS v3.1 base score of 7.5 (High), assigned by ISC (ISC Advisory, Openwall OSS-Sec).
The root cause is classified as CWE-617 (Reachable Assertion): when named processes a malformed BRID (Binding Record ID) or HHIT (Hash-Based Host Identity Tag) DNS resource record, an internal assertion check fails, causing the process to abort. The attack vector is network-based, requiring no authentication, no user interaction, and low complexity — an unauthenticated remote attacker can send a single crafted DNS query or response containing the malformed record to trigger the crash. No public proof-of-concept exploit code has been identified at this time (ISC Advisory, Feedly).
Successful exploitation results in an unexpected termination of the named process, causing a complete outage of DNS resolution services on the affected system. This is a pure availability impact — there is no confidentiality or integrity compromise. Dependent applications and services relying on the affected DNS server for name resolution will be disrupted, and in critical infrastructure environments, this could cascade to broader service outages (ISC Advisory, Industrial Cyber).
named's record parsing logic.named process encounters the assertion failure while parsing the malformed record and terminates unexpectedly, taking DNS services offline.named process crash entries in system logs (e.g., /var/log/syslog, /var/log/messages) showing assertion failure messages; core dump files generated in the BIND working directory.named process; repeated restarts of the named service in a short time window as recorded by systemd or init logs.named.core or similar) in the BIND working directory or /var/named/ (ISC Advisory).ISC has released patched versions: BIND 9.18.44, 9.20.18, and 9.21.17 (and corresponding Subscription Edition updates). Operators should upgrade to these versions immediately. As a network-level workaround, restrict DNS query sources to trusted clients using ACLs in named.conf (e.g., allow-query) to reduce exposure. Implementing automated service restart mechanisms (e.g., systemd Restart=on-failure) can reduce downtime if exploitation occurs. DNS firewall rules filtering unusual record types at network ingress may also provide partial mitigation (ISC Advisory, Openwall OSS-Sec).
The vulnerability was discovered and responsibly disclosed by Marlink Cyber, which published a dedicated knowledge hub article highlighting the risk to critical infrastructure DNS services (Marlink Cyber). The Canadian Centre for Cyber Security issued advisory AV26-049 covering this flaw (CCCS). Security media including GBHackers, SecurityOnline, and The Hacker News weekly recap covered the vulnerability, emphasizing the remote crash risk. The CVE appeared in multiple "Top 10 Trending CVEs" Reddit posts for the week of January 21–25, 2026, reflecting notable community interest. Downstream distributions including Debian, Fedora, and Slackware issued updated packages shortly after disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."