CVE-2025-40778: Cache poisoning attacks with unsolicited RRs
Cache poisoning attacks with unsolicited RRs
Other sources
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.18.41 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.15 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.21.14 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.18.41-S1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.20.15-S1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40778?
CVE-2025-40778 has been classified with a high severity rating due to its potential to allow cache poisoning through forged data.
How do I fix CVE-2025-40778?
To fix CVE-2025-40778, update BIND to version 9.16.51 or later, or to the latest available version in affected release branches.
Which versions of BIND are affected by CVE-2025-40778?
CVE-2025-40778 affects BIND versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, and 9.21.0 through 9.21.12.
What types of attacks can CVE-2025-40778 facilitate?
CVE-2025-40778 can facilitate cache poisoning attacks, where an attacker injects malicious DNS responses into the cache.
Is there a workaround for CVE-2025-40778?
Currently, the recommended solution for CVE-2025-40778 is to apply the appropriate software updates rather than seeking temporary workarounds.