CVE-2025-40776
published 2025-07-16CVE-2025-40776: A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9…
PriorityP349high8.6CVSS 3.1
AVNACLPRNUINSCCNIHAN
EPSS
0.21%
10.9th percentile
A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack.
This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | bind9 | — | — |
| isc | bind | >= 0 < 9.20.11-r0 | 9.20.11-r0 |
| isc | bind | >= 0 < 9.20.11-r0 | 9.20.11-r0 |
| isc | bind_9 | 9.11.3-S1 – 9.16.50-S1 | — |
| isc | bind_9 | 9.18.11-S1 – 9.18.37-S1 | — |
| isc | bind_9 | 9.20.9-S1 – 9.20.10-S1 | — |
CVSS provenance
nvdv3.18.6HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
osv8.6HIGH
vendor_debian8.6LOW
vendor_redhat8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
bind: Birthday Attack against Resolvers supporting ECS
vendor_redhat·2025-07-16·CVSS 8.6
CVE-2025-40776 [HIGH] CWE-349 bind: Birthday Attack against Resolvers supporting ECS
bind: Birthday Attack against Resolvers supporting ECS
A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack.
This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.
A flaw was found in the `named` caching resolver, a component of BIND 9. When this resolver is configured to send EDNS Client Subnet (ECS) options, it may be vulnerable to a cache-poisoning attack. A remote attacker could exploit this to compromise the integrity of cached DNS data. This could lead to users being redirected to malicious websites or services. EDNS Client Subnet (ECS) options are only available in the BIND Subscription Edition (-S), so only the -S edition is af
Debian
CVE-2025-40776: bind9 - A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) o...
vendor_debian·2025·CVSS 8.6
CVE-2025-40776 [HIGH] CVE-2025-40776: bind9 - A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) o...
A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
OSV
CVE-2025-40776: A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack
osv·2025-07-16·CVSS 8.6
CVE-2025-40776 [HIGH] CVE-2025-40776: A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack
A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack.
This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.
GHSA
GHSA-2hm8-9847-q7gc: A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack
ghsa_unreviewed·2025-07-16
CVE-2025-40776 [HIGH] CWE-349 GHSA-2hm8-9847-q7gc: A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack
A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack.
This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.
No detection rules found.
No public exploits indexed.
2025-07-16
Published