Insufficient verification of data authenticity in ISC BIND - CVE-2025-40778

 

Insufficient verification of data authenticity in ISC BIND - CVE-2025-40778

Published: October 23, 2025 / Updated: October 31, 2025


Vulnerability identifier: #VU117610
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N]
CVE-ID: CVE-2025-40778
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to poison DNS cache.

The vulnerability exists due to insufficient verification of data authenticity when accepting records from answers. A remote attacker can inject forged data into the cache leading to DNS cache poisoning. 


Affected software

ISC BIND
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise Server 15 SP4
Debian Linux
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Manager Proxy 4.3
SUSE Manager Retail Branch Server 4.3
SUSE Manager Server 4.3
SUSE Linux Enterprise Server 15 SP3
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Manager Client Tools for SLE Micro
SUSE Multi-Linux Manager Client Tools for SLE Micro
Anolis OS
SUSE Enterprise Storage
IBM i
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Server Applications Module
Basesystem Module
openSUSE Leap
openEuler
Ubuntu
Fedora
Netezza Appliance
Financial Transaction Manager for RedHat OpenShift
Total Storage Service Console (TSSC) / TS4500 IMC
IBM Qradar SIEM
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
dhcp
dhcp-debuginfo
dhcp-help
dhcp-devel
dhcp-debugsource
bind (Red Hat package) main
bind-export-libs
bind
bind-chroot
bind-devel
bind-export-devel
bind-libs
bind-libs-lite
bind-lite-devel
bind-pkcs11
bind-pkcs11-devel
bind-pkcs11-libs
bind-utils
bind-license
bind-sdb
bind-sdb-chroot
bind-pkcs11-utils
python3-bind
bind-debugsource
bind-debuginfo
libisc1107-debuginfo
libisccc161-debuginfo
libisccfg163
bind-utils-debuginfo
libdns1110-debuginfo
libirs161-debuginfo
bind-chrootenv
libdns1110
libisccc161
liblwres161-debuginfo
libisc1107
libirs161
libbind9-161-debuginfo
libisccfg163-debuginfo
liblwres161
libbind9-161
python-bind
bind-doc
libisc1107-32bit
libisc1107-debuginfo-32bit
libisccfg1600-debuginfo
libirs1601-debuginfo
libisc1606-debuginfo
libirs1601
libns1604-debuginfo
libisccfg1600
libisccc1600-debuginfo
libbind9-1600-debuginfo
libisc1606
libbind9-1600
libdns1605-64bit
libisccfg1600-64bit
libbind9-1600-64bit
libisccc1600-64bit
libirs1601-64bit
libisc1606-64bit
libdns1605
libisccc1600
libdns1605-debuginfo
libns1604
libirs-devel
bind9.16 (Red Hat package)
bind9.16-utils
bind9.16
bind9.16-chroot
bind9.16-devel
bind9.16-libs
bind9.16-dnssec-utils
bind9.16-license
python3-bind9.16
bind-dnssec-doc
bind-dnssec-utils
bind9.18 (Red Hat package)
bind9 (Ubuntu package)
bind9 (Debian package)
bind9-next
bind-dyndb-ldap
Red Hat OpenShift Serverless
OpenShift Virtualization
Cryostat
Red Hat OpenShift Container Platform

How to mitigate CVE-2025-40778

Install updates from vendor's website.

ISC BIND - addressed in versions 9.18.41, 9.18.41-S1, 9.20.15, 9.20.15-S1, 9.21.14
Netezza Appliance - update to 1.0.0.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 14 IF02
Red Hat OpenShift Serverless - update to 1
Cryostat - update to 4.1.0
dhcp - addressed in versions 4.4.2-16, 4.4.3-11, 4.4.3-12, 4.4.3-13
dhcp-debuginfo - addressed in versions 4.4.2-16, 4.4.3-11, 4.4.3-12, 4.4.3-13
dhcp-help - addressed in versions 4.4.2-16, 4.4.3-11, 4.4.3-12, 4.4.3-13
dhcp-devel - addressed in versions 4.4.2-16, 4.4.3-11, 4.4.3-12, 4.4.3-13
dhcp-debugsource - addressed in versions 4.4.2-16, 4.4.3-11, 4.4.3-12, 4.4.3-13
Red Hat OpenShift Container Platform - addressed in versions 4.12.84, 4.13.63, 4.14.61, 4.15.61, 4.16.55, 4.17.47, 4.18.31, 4.19.22, 4.20.10
OpenShift Virtualization - update to 4.19.17
bind (Red Hat package) main - addressed in versions 9.8.2-0.68.rc1.el6_10.17, 9.11.4-26.P2.el7_9.19, 9.11.13-6.el8_2.11, 9.11.36-3.el8_6.11, 9.11.36-8.el8_8.8, 9.11.36-16.el8_10.6, 9.16.23-1.el9_0.11, 9.16.23-11.el9_2.9, 9.16.23-18.el9_4.10, 9.18.33-4.el10_0.2, 9.18.33-10.el10_1.2
bind-export-libs - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1
bind - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1, 9.18.34-3
bind-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1, 9.18.34-3
bind-devel - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1, 9.18.34-3
bind-export-devel - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1
bind-libs - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1, 9.18.34-3
bind-libs-lite - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1
bind-lite-devel - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1
bind-pkcs11 - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1
bind-pkcs11-devel - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1
bind-pkcs11-libs - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1
bind-utils - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1, 9.18.34-3
bind-license - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1, 9.18.34-3
bind-sdb - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1
bind-sdb-chroot - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1
bind-pkcs11-utils - addressed in versions 9.11.4-26.P2, 9.11.36-16.0.1
python3-bind - addressed in versions 9.11.21-22, 9.16.23-28
bind-utils - addressed in versions 9.11.21-22, 9.16.23-28, 9.18.21-5
bind-pkcs11-devel - addressed in versions 9.11.21-22, 9.16.23-28
bind-pkcs11 - addressed in versions 9.11.21-22, 9.16.23-28
bind-libs-lite - update to 9.11.21-22
bind-libs - addressed in versions 9.11.21-22, 9.16.23-28, 9.18.21-5
bind-export-devel - update to 9.11.21-22
bind-devel - addressed in versions 9.11.21-22, 9.16.23-28, 9.18.21-5
bind-debugsource - addressed in versions 9.11.21-22, 9.16.23-28, 9.18.21-5
bind-debuginfo - addressed in versions 9.11.21-22, 9.16.23-28, 9.18.21-5
bind-chroot - addressed in versions 9.11.21-22, 9.16.23-28, 9.18.21-5
bind - addressed in versions 9.11.21-22, 9.16.23-28, 9.18.21-5
bind-export-libs - update to 9.11.21-22
libisc1107-debuginfo - update to 9.11.22-3.65.1
libisccc161-debuginfo - update to 9.11.22-3.65.1
libisccfg163 - update to 9.11.22-3.65.1
bind-utils-debuginfo - addressed in versions 9.11.22-3.65.1, 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1, 9.16.50-150400.5.56.1, 9.16.50-150500.8.32.1, 9.18.33-150600.3.18.1, 9.20.15-150700.3.12.1
libdns1110-debuginfo - update to 9.11.22-3.65.1
libirs161-debuginfo - update to 9.11.22-3.65.1
bind-chrootenv - addressed in versions 9.11.22-3.65.1, 9.16.6-150300.22.53.1
libdns1110 - update to 9.11.22-3.65.1
libisccc161 - update to 9.11.22-3.65.1
liblwres161-debuginfo - update to 9.11.22-3.65.1
bind - addressed in versions 9.11.22-3.65.1, 9.16.6-150300.22.53.1, 9.16.50-150400.5.56.1, 9.16.50-150500.8.32.1, 9.18.33-150600.3.18.1, 9.20.15-150700.3.12.1
bind-utils - addressed in versions 9.11.22-3.65.1, 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1, 9.16.50-150400.5.56.1, 9.16.50-150500.8.32.1, 9.18.33-150600.3.18.1, 9.20.15-150700.3.12.1
bind-debugsource - addressed in versions 9.11.22-3.65.1, 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1, 9.16.50-150400.5.56.1, 9.16.50-150500.8.32.1, 9.18.33-150600.3.18.1, 9.20.15-150700.3.12.1
libisc1107 - update to 9.11.22-3.65.1
bind-devel - addressed in versions 9.11.22-3.65.1, 9.16.6-150300.22.53.1
libirs161 - update to 9.11.22-3.65.1
libbind9-161-debuginfo - update to 9.11.22-3.65.1
libisccfg163-debuginfo - update to 9.11.22-3.65.1
liblwres161 - update to 9.11.22-3.65.1
bind-debuginfo - addressed in versions 9.11.22-3.65.1, 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1, 9.16.50-150400.5.56.1, 9.16.50-150500.8.32.1, 9.18.33-150600.3.18.1, 9.20.15-150700.3.12.1
libbind9-161 - update to 9.11.22-3.65.1
python-bind - update to 9.11.22-3.65.1
bind-doc - addressed in versions 9.11.22-3.65.1, 9.16.6-150300.22.53.1, 9.16.50-150400.5.56.1, 9.16.50-150500.8.32.1, 9.18.33-150600.3.18.1, 9.20.15-150700.3.12.1
libisc1107-32bit - update to 9.11.22-3.65.1
libisc1107-debuginfo-32bit - update to 9.11.22-3.65.1
python3-bind - update to 9.11.36-16.0.1
libisccfg1600-debuginfo - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libirs1601-debuginfo - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libisc1606-debuginfo - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libirs1601 - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libns1604-debuginfo - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libisccfg1600 - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libisccc1600-debuginfo - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libbind9-1600-debuginfo - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libisc1606 - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libbind9-1600 - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libdns1605-64bit - update to 9.16.6-150000.12.85.1
libisccfg1600-64bit - update to 9.16.6-150000.12.85.1
libbind9-1600-64bit - update to 9.16.6-150000.12.85.1
libisccc1600-64bit - update to 9.16.6-150000.12.85.1
libirs1601-64bit - update to 9.16.6-150000.12.85.1
libisc1606-64bit - update to 9.16.6-150000.12.85.1
python3-bind - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1, 9.16.50-150400.5.56.1, 9.16.50-150500.8.32.1
libdns1605 - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libisccc1600 - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libdns1605-debuginfo - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libns1604 - addressed in versions 9.16.6-150000.12.85.1, 9.16.6-150300.22.53.1
libirs-devel - update to 9.16.6-150300.22.53.1
bind9.16 (Red Hat package) - addressed in versions 9.16.23-0.7.el8_6.9, 9.16.23-0.14.el8_8.7, 9.16.23-0.22.el8_10.4
bind9.16-utils - update to 9.16.23-0.22
bind9.16 - update to 9.16.23-0.22
bind9.16-chroot - update to 9.16.23-0.22
bind9.16-devel - update to 9.16.23-0.22
bind9.16-libs - update to 9.16.23-0.22
bind9.16-dnssec-utils - update to 9.16.23-0.22
bind9.16-license - update to 9.16.23-0.22
python3-bind9.16 - update to 9.16.23-0.22
bind-license - addressed in versions 9.16.23-28, 9.18.21-5
bind-dnssec-doc - addressed in versions 9.16.23-28, 9.18.21-5
bind-pkcs11-utils - update to 9.16.23-28
bind-pkcs11-libs - update to 9.16.23-28
bind-dnssec-utils - addressed in versions 9.16.23-28, 9.18.21-5
bind9.18 (Red Hat package) - update to 9.18.29-5.el9_7.2
bind9 (Ubuntu package) - addressed in versions 1:9.18.30-0ubuntu0.20.04.2+esm1, 1:9.18.39-0ubuntu0.22.04.2, 1:9.18.39-0ubuntu0.24.04.2, 1:9.20.11-0ubuntu0.2, 1:9.20.11-1ubuntu2.1
bind-dnssec-utils - update to 9.18.34-3
bind-dnssec-doc - update to 9.18.34-3
bind-doc - update to 9.18.34-3
bind - addressed in versions 9.18.41-1.fc41, 9.18.41-1.fc42, 9.18.41-1.fc43, 9.18.41-1.fc44
bind9 (Debian package) - addressed in versions 1:9.18.41-1~deb12u1, 1:9.20.15-1~deb13u1
bind9-next - update to 9.21.14-2.fc43
bind-dyndb-ldap - addressed in versions 11.10-35.fc41, 11.11-7.fc42, 11.11-8.fc43, 11.11-8.fc44

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins