CVE-2025-40775: DNS message with invalid TSIG causes an assertion failure
DNS message with invalid TSIG causes an assertion failure
Other sources
When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.
— NVD
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40775?
CVE-2025-40775 has a severity rating that indicates a potential for exploitation due to assertion failure.
How do I fix CVE-2025-40775?
To fix CVE-2025-40775, you should update BIND to the latest available version beyond 9.20.8 and 9.21.7.
Which versions of BIND are affected by CVE-2025-40775?
CVE-2025-40775 affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.
What impact does CVE-2025-40775 have on system security?
CVE-2025-40775 can lead to a denial of service due to BIND aborting when encountering an invalid TSIG algorithm.
Is CVE-2025-40775 a critical vulnerability?
CVE-2025-40775 is considered critical due to the potential for causing service disruptions.