CVE-2025-40776

CWE-3495 documents5 sources
Severity
8.6HIGH
EPSS
0.0%
top 97.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 16

Description

A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:NExploitability: 3.9 | Impact: 4.0

Affected Packages2 packages

Alpinebind< 9.20.11-r0+1
CVEListV5isc/bind_99.11.3-S19.16.50-S1+2

🔴Vulnerability Details

3
OSV
CVE-2025-40776: A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack2025-07-16
CVEList
Birthday Attack against Resolvers supporting ECS2025-07-16
GHSA
GHSA-2hm8-9847-q7gc: A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack2025-07-16

📋Vendor Advisories

1
Debian
CVE-2025-40776: bind9 - A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) o...2025