Bug 2406399

Summary: CVE-2025-40778 [Severity: High] bind9: Cache poisoning attacks with unsolicited RRs
Product: [Fedora] Fedora Reporter: pgnd <pgnd>
Component: bind9-nextAssignee: Petr Menšík <pemensik>
Status: CLOSED ERRATA QA Contact:
Severity: high Docs Contact:
Priority: unspecified    
Version: 42CC: dns-sig, pemensik, pspacek
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: Unspecified   
OS: Linux   
URL: https://www.cve.org/CVERecord?id=CVE-2025-40778
Whiteboard:
Fixed In Version: bind9-next-9.21.14-2.fc42 bind9-next-9.21.14-2.fc43 Doc Type: ---
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2025-11-16 00:54:59 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2405827, 2405829, 2405830, 2394406    
Bug Blocks:    

Description pgnd 2025-10-26 13:44:50 UTC
9.21.14 update resolves

 CVE-2025-40778: Cache poisoning attacks with unsolicited RRs New
  Published on Oct 22, 2025
  https://kb.isc.org/docs/cve-2025-40778

CVSS Score: 8.6
Versions affected:  BIND
 9.11.0 -> 9.16.50
 9.18.0 -> 9.18.39
 9.20.0 -> 9.20.13
 9.21.0 -> 9.21.12  <---------------


Reproducible: Always

Comment 1 pgnd 2025-10-30 11:22:39 UTC
https://downloads.isc.org/isc/bind9/9.21.14/doc/arm/html/notes.html#security-fixes

9.21.14 update resolves

CVE-2025-8677: Resource exhaustion via malformed DNSKEY handling
 Severity: High
	https://kb.isc.org/docs/cve-2025-8677

CVE-2025-40778: Cache poisoning attacks with unsolicited RRs
 Severity: High
	https://kb.isc.org/docs/cve-2025-40778

CVE-2025-40780: Cache poisoning due to weak PRNG
 Severity: High
	https://kb.isc.org/docs/cve-2025-40780

Comment 2 Petr Menšík 2025-11-06 15:39:19 UTC
Yes, I know they are there. I was quite busy in previous days working on RHEL patches, which are still not delivered to our customers. In fedora is fixing it simpler, but I have only two eyes and two hands.

I understand, but this development version is kind of last one to process when everything else is finished. Fortunately this does not need building together with bind-dyndb-ldap. But sure, it is taking enough time.

Comment 3 Fedora Update System 2025-11-07 10:58:19 UTC
FEDORA-2025-b68f7f541d (bind9-next-9.21.14-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-b68f7f541d

Comment 4 Fedora Update System 2025-11-07 10:58:49 UTC
FEDORA-2025-d9f9394ecd (bind9-next-9.21.14-2.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-d9f9394ecd

Comment 5 Petr Menšík 2025-11-07 11:44:27 UTC
I am not sure whether I should escalate no bind9-next CVE bugs created, but I always fix CVEs for for this development version by rebases anyway.

Comment 6 Fedora Update System 2025-11-08 02:03:14 UTC
FEDORA-2025-b68f7f541d has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-b68f7f541d`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-b68f7f541d

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2025-11-08 02:19:32 UTC
FEDORA-2025-d9f9394ecd has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-d9f9394ecd`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-d9f9394ecd

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 8 Fedora Update System 2025-11-16 00:54:59 UTC
FEDORA-2025-d9f9394ecd (bind9-next-9.21.14-2.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 9 Fedora Update System 2025-11-16 01:20:22 UTC
FEDORA-2025-b68f7f541d (bind9-next-9.21.14-2.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.