CVE Vulnerabilities

CVE-2025-40778

Acceptance of Extraneous Untrusted Data With Trusted Data

Published: Oct 22, 2025 | Modified: Nov 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.6 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

Weakness

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

Affected Software

NameVendorStart VersionEnd Version
Red Hat Enterprise Linux 10RedHatbind-32:9.18.33-4.el10_0.2*
Red Hat Enterprise Linux 10RedHatbind-32:9.18.33-10.el10_1.2*
Red Hat Enterprise Linux 6 Extended Lifecycle Support - EXTENSIONRedHatbind-32:9.8.2-0.68.rc1.el6_10.17*
Red Hat Enterprise Linux 7 Extended Lifecycle SupportRedHatbind-32:9.11.4-26.P2.el7_9.19*
Red Hat Enterprise Linux 8RedHatbind9.16-32:9.16.23-0.22.el8_10.4*
Red Hat Enterprise Linux 8RedHatbind-32:9.11.36-16.el8_10.6*
Red Hat Enterprise Linux 8RedHatbind-32:9.11.36-16.el8_10.6*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatbind-32:9.11.13-6.el8_2.11*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatbind-32:9.11.26-4.el8_4.8*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatbind-32:9.11.26-4.el8_4.8*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatbind-32:9.11.36-3.el8_6.11*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatbind9.16-32:9.16.23-0.7.el8_6.9*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatbind-32:9.11.36-3.el8_6.11*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatbind9.16-32:9.16.23-0.7.el8_6.9*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatbind-32:9.11.36-3.el8_6.11*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatbind9.16-32:9.16.23-0.7.el8_6.9*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatbind-32:9.11.36-8.el8_8.8*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatbind9.16-32:9.16.23-0.14.el8_8.7*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatbind-32:9.11.36-8.el8_8.8*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatbind9.16-32:9.16.23-0.14.el8_8.7*
Red Hat Enterprise Linux 9RedHatbind9.18-32:9.18.29-4.el9_6.2*
Red Hat Enterprise Linux 9RedHatbind-32:9.16.23-31.el9_6.2*
Red Hat Enterprise Linux 9RedHatbind-32:9.16.23-34.el9_7.1*
Red Hat Enterprise Linux 9RedHatbind9.18-32:9.18.29-5.el9_7.2*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatbind-32:9.16.23-1.el9_0.11*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatbind-32:9.16.23-11.el9_2.9*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatbind-32:9.16.23-18.el9_4.10*
Red Hat OpenShift Container Platform 4.12RedHatrhcos-412.86.202601061735-0*
Red Hat OpenShift Container Platform 4.13RedHatrhcos-413.92.202601130113-0*
Red Hat OpenShift Container Platform 4.14RedHatrhcos-414.92.202601191325-0*
Red Hat OpenShift Container Platform 4.16RedHatrhcos-416.94.202601071926-0*
Red Hat OpenShift Container Platform 4.17RedHatrhcos-417.94.202601120213-0*
Red Hat OpenShift Container Platform 4.18RedHatrhcos-418.94.202601071817-0*
Red Hat OpenShift Container Platform 4.19RedHatrhcos-4.19.9.6.202601130152-0*
Red Hat OpenShift Container Platform 4.20RedHatrhcos-4.20.9.6.202601052146-0*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-data-index-ephemeral-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-data-index-postgresql-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-db-migrator-tool-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.36.0-10*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.36.0-10*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.36.0-4*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-management-console-rhel8:1.36.0-9*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-operator-bundle:1.36.0-12*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-rhel8-operator:1.36.0-18*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-swf-builder-rhel8:1.36.0-11*
RHOSS-1.36-RHEL-8RedHatopenshift-serverless-1/logic-swf-devmode-rhel8:1.36.0-7*
Red Hat Discovery 2RedHatdiscovery/discovery-ui-rhel9:sha256:69cb9c84b806ee2f448bdbbcf3174855432f5caec8f31ca2a345655da4a72f57*
Bind9Ubuntudevel*
Bind9Ubuntuesm-infra/bionic*
Bind9Ubuntuesm-infra/focal*
Bind9Ubuntujammy*
Bind9Ubuntunoble*
Bind9Ubuntuplucky*
Bind9Ubuntuquesting*
Bind9Ubuntuupstream*
Isc-dhcpUbuntuplucky*

References