https://seclists.org/oss-sec/2025/q4/68: ISC has disclosed the vulnerabilities in BIND 9 (CVE-2025-8677, CVE-2025-40778, CVE-2025-40780)
Published Oct 22, 2025
·Updated
Affected Software
1 affected component
Internet Systems Consortium BIND 9
Frequently Asked Questions
1
What is the severity of CVE-2025-8677?
CVE-2025-8677 is classified as a high severity vulnerability due to its potential for resource exhaustion in BIND 9.
2
How do I fix CVE-2025-8677?
To fix CVE-2025-8677, upgrade to the latest version of BIND 9 as recommended by the Internet Systems Consortium.
3
What is CVE-2025-40778 related to?
CVE-2025-40778 is related to cache poisoning attacks resulting from the acceptance of unsolicited resource records.
4
How can I mitigate CVE-2025-40778 in BIND 9?
Mitigation for CVE-2025-40778 involves applying patches provided by ISC and reviewing DNS security configurations.
5
What might happen if I ignore CVE-2025-40780?
Ignoring CVE-2025-40780 can lead to negative impacts on the integrity of DNS responses, allowing potential exploitation.