CVE Vulnerabilities

CVE-2025-40778

Acceptance of Extraneous Untrusted Data With Trusted Data

Published: Oct 22, 2025 | Modified: Nov 04, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.6 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Ubuntu
MEDIUM

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

Weakness

The product, when processing trusted data, accepts any untrusted data that is also included with the trusted data, treating the untrusted data as if it were trusted.

Affected Software

Name Vendor Start Version End Version
Red Hat Enterprise Linux 10 RedHat bind-32:9.18.33-4.el10_0.2 *
Red Hat Enterprise Linux 10 RedHat bind-32:9.18.33-10.el10_1.2 *
Red Hat Enterprise Linux 8 RedHat bind9.16-32:9.16.23-0.22.el8_10.4 *
Red Hat Enterprise Linux 8 RedHat bind-32:9.11.36-16.el8_10.6 *
Red Hat Enterprise Linux 8 RedHat bind-32:9.11.36-16.el8_10.6 *
Red Hat Enterprise Linux 8.2 Advanced Update Support RedHat bind-32:9.11.13-6.el8_2.11 *
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support RedHat bind-32:9.11.26-4.el8_4.8 *
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On RedHat bind-32:9.11.26-4.el8_4.8 *
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support RedHat bind-32:9.11.36-3.el8_6.11 *
Red Hat Enterprise Linux 8.6 Telecommunications Update Service RedHat bind-32:9.11.36-3.el8_6.11 *
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions RedHat bind-32:9.11.36-3.el8_6.11 *
Red Hat Enterprise Linux 8.8 Telecommunications Update Service RedHat bind-32:9.11.36-8.el8_8.8 *
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions RedHat bind-32:9.11.36-8.el8_8.8 *
Red Hat Enterprise Linux 9 RedHat bind9.18-32:9.18.29-4.el9_6.2 *
Red Hat Enterprise Linux 9 RedHat bind-32:9.16.23-31.el9_6.2 *
Red Hat Enterprise Linux 9 RedHat bind-32:9.16.23-34.el9_7.1 *
Red Hat Enterprise Linux 9 RedHat bind9.18-32:9.18.29-5.el9_7.2 *
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions RedHat bind-32:9.16.23-1.el9_0.11 *
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions RedHat bind-32:9.16.23-11.el9_2.9 *
Red Hat Enterprise Linux 9.4 Extended Update Support RedHat bind-32:9.16.23-18.el9_4.10 *
Bind9 Ubuntu devel *
Bind9 Ubuntu esm-infra/bionic *
Bind9 Ubuntu esm-infra/focal *
Bind9 Ubuntu jammy *
Bind9 Ubuntu noble *
Bind9 Ubuntu plucky *
Bind9 Ubuntu questing *
Bind9 Ubuntu upstream *

References