In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use.
This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
References
| Link | Resource |
|---|---|
| https://kb.isc.org/docs/cve-2025-40780 |
Configurations
No configuration.
History
22 Oct 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-22 16:15
Updated : 2025-10-22 21:12
NVD link : CVE-2025-40780
Mitre link : CVE-2025-40780
CVE.ORG link : CVE-2025-40780
JSON object : View
Products Affected
No product.
CWE
CWE-341
Predictable from Observable State
