Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-40775

Опубликовано: 21 мая 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 7.5

Описание

When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.

РелизСтатусПримечание
devel

released

1:9.20.4-3ubuntu2
esm-infra-legacy/trusty

not-affected

esm-infra/bionic

not-affected

esm-infra/focal

not-affected

1:9.18.30-0ubuntu0.20.04.2
esm-infra/xenial

not-affected

focal

not-affected

1:9.18.30-0ubuntu0.20.04.2
jammy

not-affected

1:9.18.30-0ubuntu0.22.04.2
noble

not-affected

1:9.18.30-0ubuntu0.24.04.2
oracular

released

1:9.20.0-2ubuntu3.2
plucky

released

1:9.20.4-3ubuntu1.1

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra/focal

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
noble

DNE

oracular

DNE

plucky

DNE

upstream

needs-triage

Показывать по

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps/noble

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
esm-infra/bionic

not-affected

code not present
esm-infra/focal

not-affected

code not present
esm-infra/xenial

not-affected

code not present
focal

not-affected

code not present
jammy

not-affected

code not present
noble

not-affected

code not present
oracular

not-affected

code not present

Показывать по

EPSS

Процентиль: 2%
0.00015
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
около 1 месяца назад

When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.

CVSS3: 7.5
nvd
около 1 месяца назад

When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.

CVSS3: 7.5
debian
около 1 месяца назад

When an incoming DNS protocol message includes a Transaction Signature ...

CVSS3: 7.5
github
около 1 месяца назад

When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.

suse-cvrf
22 дня назад

Security update for bind

EPSS

Процентиль: 2%
0.00015
Низкий

7.5 High

CVSS3