Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-40776

Опубликовано: 16 июл. 2025
Источник: redhat
CVSS3: 8.6

Описание

A named caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

A flaw was found in the named caching resolver, a component of BIND 9. When this resolver is configured to send EDNS Client Subnet (ECS) options, it may be vulnerable to a cache-poisoning attack. A remote attacker could exploit this to compromise the integrity of cached DNS data. This could lead to users being redirected to malicious websites or services. EDNS Client Subnet (ECS) options are only available in the BIND Subscription Edition (-S), so only the -S edition is affected by this CVE.

Отчет

Red Hat does not ship the BIND Subscription Edition.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10bindNot affected
Red Hat Enterprise Linux 6bindNot affected
Red Hat Enterprise Linux 7bindNot affected
Red Hat Enterprise Linux 8bindNot affected
Red Hat Enterprise Linux 8bind9.16Not affected
Red Hat Enterprise Linux 9bindNot affected
Red Hat Enterprise Linux 9bind9.18Not affected
Red Hat Enterprise Linux 9dhcpNot affected
Red Hat Hardened ImagesbindNot affected
Red Hat OpenShift Container Platform 4rhcosNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-349
https://bugzilla.redhat.com/show_bug.cgi?id=2380930bind: Birthday Attack against Resolvers supporting ECS

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
ubuntu
около 1 года назад

A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

CVSS3: 8.6
nvd
около 1 года назад

A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

msrc
10 дней назад

Birthday Attack against Resolvers supporting ECS

CVSS3: 8.6
debian
около 1 года назад

A `named` caching resolver that is configured to send ECS (EDNS Client ...

CVSS3: 8.6
github
около 1 года назад

A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

8.6 High

CVSS3