CVE-2025-40777 is a remotely exploitable denial-of-service vulnerability in BIND 9 named when operating as a caching resolver with the serve-stale feature enabled. If serve-stale-enable is set to yes and stale-answer-client-timeout is set to 0, resolution of a query that traverses a specific CNAME chain involving a particular combination of cached and authoritative data can trigger a reachable assertion failure in the resolver logic. The failure occurs in the query-processing path and causes named to abort. The issue affects BIND 9.20.0 through 9.20.10, 9.21.0 through 9.21.9, and 9.20.9-S1 through 9.20.10-S1. Resolver deployments are affected; authoritative-only service is believed to be unaffected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
named daemon to terminate, producing a denial-of-service condition against the affected recursive resolver. Because the issue is remotely reachable through crafted DNS query patterns and requires no authentication or user interaction, an attacker able to send queries to the resolver can repeatedly crash the service and disrupt name resolution availability for downstream clients. No confidentiality or integrity impact has been established for this CVE; the documented effect is service interruption.If you can’t patch tonight, do this now.
stale-answer-client-timeout to disabled or by disabling serve-stale functionality. Disabling serve-stale-enable prevents the assertion condition. Restricting recursive query access to trusted clients can reduce exposure, but it does not remove the underlying flaw on reachable resolvers.Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
16 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously fixed BIND serve-stale flag-handling bug involving DNS_DBFIND_STALETIMEOUT, referenced here as a closely related prior vulnerability and comparison point for the newly described STALEOK flag leak.
An assertion-failure denial-of-service vulnerability in ISC BIND 9 triggered when using the 'stale-answer-client-timeout 0' option under specific stale-cache/serve-stale conditions, causing named to crash.
A high-severity remotely exploitable denial-of-service vulnerability in BIND named caching resolvers that can cause the daemon to abort with an assertion failure under specific serve-stale and CNAME-chain conditions.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.