A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack.
This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.
References
Link | Resource |
---|---|
https://kb.isc.org/docs/cve-2025-40776 |
Configurations
No configuration.
History
16 Jul 2025, 14:58
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-16 14:15
Updated : 2025-07-16 14:58
NVD link : CVE-2025-40776
Mitre link : CVE-2025-40776
CVE.ORG link : CVE-2025-40776
JSON object : View
Products Affected
No product.
CWE
CWE-349
Acceptance of Extraneous Untrusted Data With Trusted Data