ISC disclosed CVE-2025-40777, a high-severity denial-of-service flaw in BIND 9 that can cause named to exit during recursive lookups when the resolver is configured as a caching resolver with serve-stale enabled and stale-answer-client-timeout 0. The bug is triggered by a specific CNAME resolution path involving stale cache behavior and can be exploited remotely against affected resolvers; authoritative-only deployments are not believed to be impacted. ISC assigned the issue CVSS 7.5 and CWE-617, said there was no known active exploitation, and identified affected releases as BIND 9.20.0 through 9.20.10, 9.21.0 through 9.21.9, and Supported Preview Edition builds.
Related BIND bug reports show the same configuration also caused stale RRsets in CNAME chains to be mishandled, with refresh queries missing or incomplete and logs incorrectly reporting stale-answer activity for records that were not yet stale. ISC said fixes and regression tests were prepared through its coordinated release process, with the vulnerability addressed in 9.20.11 and 9.21.10 and the stale-refresh bug later fixed in 9.20.12 and 9.21.11. As a workaround, ISC advised operators to upgrade or disable the vulnerable stale-answer settings until patched versions are deployed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
An ISC GitLab issue for CVE-2025-40777 recorded that fixes and regression tests had been prepared and merged as part of ISC's coordinated release process. The issue described a reproducible crash path involving `zemanta-nychi2.outbrain.org`, low-TTL data, and stale-answer refresh logic.
ISC published a knowledge base advisory for CVE-2025-40777 listing affected BIND 9.20.0-9.20.10 and 9.21.0-9.21.9 versions, stating authoritative services were believed unaffected. The advisory recommended upgrading to BIND 9.20.11 or 9.21.10 or disabling the vulnerable stale-answer settings as a workaround.
An ISC GitLab issue documented a bug where stale RRsets in a CNAME chain were not always refreshed correctly when `stale-answer-client-timeout` was set to 0. The report also noted misleading stale-answer log messages and identified BIND 9.18.33 and the bind-9.18 branch as affected.
ISC publicly disclosed CVE-2025-40777, a high-severity denial-of-service flaw in BIND resolvers tied to the use of `stale-answer-client-timeout 0`. The issue can cause `named` to crash during recursive lookups involving stale cache behavior.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
gitlab.isc.org
Open sourcekb.isc.org
Open sourcegitlab.isc.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.