Vulnerability Description
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://kb.isc.org/docs/cve-2025-40778
- http://www.openwall.com/lists/oss-security/2025/10/22/1
- https://gist.github.com/N3mes1s/f76b4a606308937b0806a5256bc1f918
FAQ
What is CVE-2025-40778?
CVE-2025-40778 is a vulnerability with a CVSS score of 8.6 (HIGH). Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16....
How severe is CVE-2025-40778?
CVE-2025-40778 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-40778?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.