CVE-2025-40776: Birthday Attack against Resolvers supporting ECS
A named caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40776?
CVE-2025-40776 is considered a high-severity vulnerability due to its potential for cache-poisoning attacks.
How do I fix CVE-2025-40776?
To fix CVE-2025-40776, upgrade your BIND 9 to versions 9.16.51-S1 or later, 9.18.38-S1 or later, or 9.20.11-S1 or later.
Which versions of BIND are affected by CVE-2025-40776?
CVE-2025-40776 affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.
What type of attack is associated with CVE-2025-40776?
CVE-2025-40776 is associated with cache-poisoning attacks facilitated by the misuse of ECS (EDNS Client Subnet) options.
What is the impact of exploiting CVE-2025-40776?
Exploiting CVE-2025-40776 can lead to incorrect DNS responses, allowing attackers to redirect users to malicious sites.