CVE-2025-40777: A possible assertion failure when 'stale-answer-client-timeout' is set to '0'
If a named caching resolver is configured with serve-stale-enable yes, and with stale-answer-client-timeout set to 0 (the only allowable value other than disabled), and if the resolver, in the process of resolving a query, encounters a CNAME chain involving a specific combination of cached or authoritative records, the daemon will abort with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.10, 9.21.0 through 9.21.9, and 9.20.9-S1 through 9.20.10-S1.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40777?
CVE-2025-40777 is classified as a medium severity vulnerability affecting ISC BIND.
How do I fix CVE-2025-40777?
To fix CVE-2025-40777, you should update your ISC BIND installation to a version that is not affected, specifically beyond the specified vulnerable versions.
What versions of ISC BIND are affected by CVE-2025-40777?
CVE-2025-40777 affects ISC BIND versions 9.20.0 through 9.20.10, 9.21.0 through 9.21.9, and 9.20.9-S1.
What is the impact of CVE-2025-40777 on DNS resolution?
CVE-2025-40777 can lead to stale DNS answers being served, potentially causing inaccurate or outdated DNS records to be cached.
Can I disable features to mitigate CVE-2025-40777?
While disabling the 'serve-stale-enable' option could provide a temporary workaround, the best practice is to upgrade to a non-vulnerable version of ISC BIND.