Bug 2406399 - CVE-2025-40778 [Severity: High] bind9: Cache poisoning attacks with unsolicited RRs
Summary: CVE-2025-40778 [Severity: High] bind9: Cache poisoning attacks with unsolicit...
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Fedora
Classification: Fedora
Component: bind9-next
Version: 42
Hardware: Unspecified
OS: Linux
unspecified
high
Target Milestone: ---
Assignee: Petr Menšík
QA Contact:
URL: https://www.cve.org/CVERecord?id=CVE-...
Whiteboard:
Depends On: CVE-2025-40778 CVE-2025-40780 CVE-2025-8677 2394406
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-10-26 13:44 UTC by pgnd
Modified: 2025-11-16 01:20 UTC (History)
3 users (show)

Fixed In Version: bind9-next-9.21.14-2.fc42 bind9-next-9.21.14-2.fc43
Clone Of:
Environment:
Last Closed: 2025-11-16 00:54:59 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Fedora Package Sources bind9-next pull-request 14 0 None None None 2025-11-06 15:39:18 UTC

Description pgnd 2025-10-26 13:44:50 UTC
9.21.14 update resolves

 CVE-2025-40778: Cache poisoning attacks with unsolicited RRs New
  Published on Oct 22, 2025
  https://kb.isc.org/docs/cve-2025-40778

CVSS Score: 8.6
Versions affected:  BIND
 9.11.0 -> 9.16.50
 9.18.0 -> 9.18.39
 9.20.0 -> 9.20.13
 9.21.0 -> 9.21.12  <---------------


Reproducible: Always

Comment 1 pgnd 2025-10-30 11:22:39 UTC
https://downloads.isc.org/isc/bind9/9.21.14/doc/arm/html/notes.html#security-fixes

9.21.14 update resolves

CVE-2025-8677: Resource exhaustion via malformed DNSKEY handling
 Severity: High
	https://kb.isc.org/docs/cve-2025-8677

CVE-2025-40778: Cache poisoning attacks with unsolicited RRs
 Severity: High
	https://kb.isc.org/docs/cve-2025-40778

CVE-2025-40780: Cache poisoning due to weak PRNG
 Severity: High
	https://kb.isc.org/docs/cve-2025-40780

Comment 2 Petr Menšík 2025-11-06 15:39:19 UTC
Yes, I know they are there. I was quite busy in previous days working on RHEL patches, which are still not delivered to our customers. In fedora is fixing it simpler, but I have only two eyes and two hands.

I understand, but this development version is kind of last one to process when everything else is finished. Fortunately this does not need building together with bind-dyndb-ldap. But sure, it is taking enough time.

Comment 3 Fedora Update System 2025-11-07 10:58:19 UTC
FEDORA-2025-b68f7f541d (bind9-next-9.21.14-2.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-b68f7f541d

Comment 4 Fedora Update System 2025-11-07 10:58:49 UTC
FEDORA-2025-d9f9394ecd (bind9-next-9.21.14-2.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2025-d9f9394ecd

Comment 5 Petr Menšík 2025-11-07 11:44:27 UTC
I am not sure whether I should escalate no bind9-next CVE bugs created, but I always fix CVEs for for this development version by rebases anyway.

Comment 6 Fedora Update System 2025-11-08 02:03:14 UTC
FEDORA-2025-b68f7f541d has been pushed to the Fedora 43 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-b68f7f541d`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-b68f7f541d

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 7 Fedora Update System 2025-11-08 02:19:32 UTC
FEDORA-2025-d9f9394ecd has been pushed to the Fedora 42 testing repository.
Soon you'll be able to install the update with the following command:
`sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2025-d9f9394ecd`
You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2025-d9f9394ecd

See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.

Comment 8 Fedora Update System 2025-11-16 00:54:59 UTC
FEDORA-2025-d9f9394ecd (bind9-next-9.21.14-2.fc42) has been pushed to the Fedora 42 stable repository.
If problem still persists, please make note of it in this bug report.

Comment 9 Fedora Update System 2025-11-16 01:20:22 UTC
FEDORA-2025-b68f7f541d (bind9-next-9.21.14-2.fc43) has been pushed to the Fedora 43 stable repository.
If problem still persists, please make note of it in this bug report.


Note You need to log in before you can comment on or make changes to this bug.