Bug 2405829 (CVE-2025-40780)

Summary: CVE-2025-40780 bind: Cache poisoning due to weak PRNG
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: michael.h.hall-1
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A vulnerability was found in BIND resolvers caused by a weakness in the Pseudo Random Number Generator (PRNG). This weakness allows an attacker to potentially predict the source port and query ID used by BIND, enabling cache poisoning attacks. If successful, the attacker can inject malicious DNS responses into the resolver’s cache, causing clients to receive spoofed DNS data. Authoritative servers are generally unaffected, but recursive resolvers are exposed to this risk. Exploitation is remote and does not require user interaction.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2394406, 2405831, 2405832, 2405833, 2405834    
Bug Blocks: 2406399    

Description OSIDB Bzimport 2025-10-22 15:22:51 UTC
In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use.

Comment 2 errata-xmlrpc 2025-11-05 11:51:23 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2025:19793 https://access.redhat.com/errata/RHSA-2025:19793

Comment 3 errata-xmlrpc 2025-11-06 15:39:25 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:19912 https://access.redhat.com/errata/RHSA-2025:19912

Comment 4 errata-xmlrpc 2025-11-10 02:34:16 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:19950 https://access.redhat.com/errata/RHSA-2025:19950

Comment 5 errata-xmlrpc 2025-11-10 02:42:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:19951 https://access.redhat.com/errata/RHSA-2025:19951

Comment 6 errata-xmlrpc 2025-11-11 19:49:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2025:21034 https://access.redhat.com/errata/RHSA-2025:21034

Comment 7 errata-xmlrpc 2025-11-12 10:34:58 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:21111 https://access.redhat.com/errata/RHSA-2025:21111

Comment 8 errata-xmlrpc 2025-11-12 10:38:49 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2025:21110 https://access.redhat.com/errata/RHSA-2025:21110

Comment 13 errata-xmlrpc 2025-11-20 07:56:40 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Extended Update Support

Via RHSA-2025:21817 https://access.redhat.com/errata/RHSA-2025:21817

Comment 14 errata-xmlrpc 2025-11-20 20:42:54 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2025:21887 https://access.redhat.com/errata/RHSA-2025:21887

Comment 15 errata-xmlrpc 2025-11-20 21:08:53 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions

Via RHSA-2025:21889 https://access.redhat.com/errata/RHSA-2025:21889

Comment 16 errata-xmlrpc 2025-11-24 10:32:17 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2025:21939 https://access.redhat.com/errata/RHSA-2025:21939

Comment 17 errata-xmlrpc 2025-11-26 07:23:52 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.6 Telecommunications Update Service

Via RHSA-2025:22168 https://access.redhat.com/errata/RHSA-2025:22168

Comment 21 errata-xmlrpc 2026-01-14 13:24:22 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.20

Via RHSA-2026:0420 https://access.redhat.com/errata/RHSA-2026:0420

Comment 22 errata-xmlrpc 2026-01-15 05:11:21 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.12

Via RHSA-2026:0316 https://access.redhat.com/errata/RHSA-2026:0316

Comment 23 errata-xmlrpc 2026-01-15 18:46:25 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.16

Via RHSA-2026:0326 https://access.redhat.com/errata/RHSA-2026:0326

Comment 24 errata-xmlrpc 2026-01-15 18:55:08 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.18

Via RHSA-2026:0332 https://access.redhat.com/errata/RHSA-2026:0332

Comment 25 errata-xmlrpc 2026-01-22 19:07:47 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.17

Via RHSA-2026:0702 https://access.redhat.com/errata/RHSA-2026:0702

Comment 26 errata-xmlrpc 2026-01-22 20:16:56 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.13

Via RHSA-2026:0677 https://access.redhat.com/errata/RHSA-2026:0677

Comment 27 errata-xmlrpc 2026-01-22 20:17:56 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.19

Via RHSA-2026:0674 https://access.redhat.com/errata/RHSA-2026:0674

Comment 28 errata-xmlrpc 2026-01-30 14:19:40 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.14

Via RHSA-2026:0996 https://access.redhat.com/errata/RHSA-2026:0996

Comment 29 errata-xmlrpc 2026-02-05 16:24:40 UTC
This issue has been addressed in the following products:

  Red Hat OpenShift Container Platform 4.15

Via RHSA-2026:1541 https://access.redhat.com/errata/RHSA-2026:1541