CVE-2025-13878
Alma Linux vulnerability analysis and mitigation

Overview

CVE-2025-13878 is a denial-of-service vulnerability in ISC BIND 9 where malformed BRID/HHIT DNS records can cause the named daemon to terminate unexpectedly due to a reachable assertion failure. Disclosed on January 21, 2026, by Internet Systems Consortium (ISC), it affects BIND 9 versions 9.18.40–9.18.43, 9.20.13–9.20.17, 9.21.12–9.21.16, and the corresponding Subscription Edition variants 9.18.40-S1–9.18.43-S1 and 9.20.13-S1–9.20.17-S1. The vulnerability was discovered and reported by Marlink Cyber. It carries a CVSS v3.1 base score of 7.5 (High), assigned by ISC (ISC Advisory, Openwall OSS-Sec).

Technical details

The root cause is classified as CWE-617 (Reachable Assertion): when named processes a malformed BRID (Binding Record ID) or HHIT (Hash-Based Host Identity Tag) DNS resource record, an internal assertion check fails, causing the process to abort. The attack vector is network-based, requiring no authentication, no user interaction, and low complexity — an unauthenticated remote attacker can send a single crafted DNS query or response containing the malformed record to trigger the crash. No public proof-of-concept exploit code has been identified at this time (ISC Advisory, Feedly).

Impact

Successful exploitation results in an unexpected termination of the named process, causing a complete outage of DNS resolution services on the affected system. This is a pure availability impact — there is no confidentiality or integrity compromise. Dependent applications and services relying on the affected DNS server for name resolution will be disrupted, and in critical infrastructure environments, this could cascade to broader service outages (ISC Advisory, Industrial Cyber).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible BIND 9 DNS servers running affected versions (9.18.40–9.18.43, 9.20.13–9.20.17, 9.21.12–9.21.16) using tools such as Shodan, Censys, or active DNS banner queries.
  2. Craft malformed record: Construct a DNS message containing a malformed BRID or HHIT resource record with invalid or unexpected field values designed to trigger the assertion failure in named's record parsing logic.
  3. Deliver the payload: Send the crafted DNS query or response packet to the target server over UDP or TCP port 53. No authentication or prior session is required.
  4. Trigger crash: The named process encounters the assertion failure while parsing the malformed record and terminates unexpectedly, taking DNS services offline.
  5. Sustain DoS: Repeatedly send malformed packets to prevent automatic service recovery, or rely on the absence of automated restart mechanisms to maintain the outage (ISC Advisory, Openwall OSS-Sec).

Indicators of compromise

  • Network: Unexpected or anomalous DNS queries/responses containing BRID or HHIT record types (DNS type codes) from unknown or external sources; high-rate DNS traffic from a single source IP targeting port 53.
  • Logs: BIND named process crash entries in system logs (e.g., /var/log/syslog, /var/log/messages) showing assertion failure messages; core dump files generated in the BIND working directory.
  • Process: Sudden absence of the named process; repeated restarts of the named service in a short time window as recorded by systemd or init logs.
  • File System: Unexpected core dump files (e.g., named.core or similar) in the BIND working directory or /var/named/ (ISC Advisory).

Mitigation and workarounds

ISC has released patched versions: BIND 9.18.44, 9.20.18, and 9.21.17 (and corresponding Subscription Edition updates). Operators should upgrade to these versions immediately. As a network-level workaround, restrict DNS query sources to trusted clients using ACLs in named.conf (e.g., allow-query) to reduce exposure. Implementing automated service restart mechanisms (e.g., systemd Restart=on-failure) can reduce downtime if exploitation occurs. DNS firewall rules filtering unusual record types at network ingress may also provide partial mitigation (ISC Advisory, Openwall OSS-Sec).

Community reactions

The vulnerability was discovered and responsibly disclosed by Marlink Cyber, which published a dedicated knowledge hub article highlighting the risk to critical infrastructure DNS services (Marlink Cyber). The Canadian Centre for Cyber Security issued advisory AV26-049 covering this flaw (CCCS). Security media including GBHackers, SecurityOnline, and The Hacker News weekly recap covered the vulnerability, emphasizing the remote crash risk. The CVE appeared in multiple "Top 10 Trending CVEs" Reddit posts for the week of January 21–25, 2026, reflecting notable community interest. Downstream distributions including Debian, Fedora, and Slackware issued updated packages shortly after disclosure.

Additional resources


SourceThis report was generated using AI

Related Alma Linux vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-47063HIGH7.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-17-openjdk-jmods
NoYesJul 21, 2026
CVE-2026-47058HIGH7.4
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.8.0-openjdk-devel
NoYesJul 21, 2026
CVE-2026-60147MEDIUM6.5
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-1.8.0-openjdk-demo
NoYesJul 21, 2026
CVE-2026-47059LOW3.7
  • Amazon Corretto JDK logoAmazon Corretto JDK
  • java-11-amazon-corretto
NoYesJul 21, 2026
CVE-2026-14957NONEN/A
  • Rocky Linux logoRocky Linux
  • libreswan
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management