CVE-2025-40776

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-40776
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-40776.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-40776
Related
Published
2025-07-16T14:15:25Z
Modified
2025-07-16T15:54:02.852226Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

A named caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

References

Affected packages

Alpine:v3.22 / bind

Package

Name
bind
Purl
pkg:apk/alpine/bind?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.20.11-r0

Affected versions

9.*

9.6.0_p1-r0
9.6.0_p1-r1
9.6.1_p1-r0
9.6.1_p1-r1
9.6.1_p2-r1
9.6.1_p3-r1
9.7.0_p1-r1
9.7.0_p1-r2
9.7.1-r0
9.7.1_p2-r0
9.7.2-r0
9.7.2_p1-r0
9.7.2_p2-r0
9.7.2_p3-r0
9.7.3-r0
9.8.0-r0
9.8.0_p1-r0
9.8.0_p2-r0
9.8.0_p2-r1
9.8.0_p4-r0
9.8.1-r0
9.8.1_p1-r0
9.9.0-r0
9.9.0-r1
9.9.1-r0
9.9.1_p1-r0
9.9.1_p2-r0
9.9.1_p3-r0
9.9.2-r0
9.9.2_p1-r0
9.9.2_p2-r0
9.9.3-r0
9.9.3_p1-r0
9.9.3_p2-r0
9.9.3_p2-r1
9.9.3_p2-r2
9.9.4-r0
9.9.4_p1-r0
9.9.4_p1-r1
9.9.4_p2-r0
9.9.5-r0
9.10.0-r0
9.10.0_p1-r0
9.10.0_p2-r0
9.10.0_p2-r1
9.10.1-r0
9.10.1-r1
9.10.1-r2
9.10.1_p1-r0
9.10.1_p2-r0
9.10.1_p2-r1
9.10.1_p2-r2
9.10.2-r0
9.10.2-r1
9.10.2_p1-r0
9.10.2_p1-r1
9.10.2_p2-r0
9.10.2_p3-r0
9.10.2_p3-r1
9.10.2_p4-r0
9.10.3-r0
9.10.3-r1
9.10.3_p2-r0
9.10.3_p3-r0
9.10.3_p3-r1
9.10.3_p4-r0
9.10.3_p4-r1
9.10.4-r0
9.10.4_p1-r0
9.10.4_p1-r1
9.10.4_p2-r0
9.10.4_p3-r0
9.10.4_p3-r1
9.10.4_p4-r0
9.10.4_p5-r0
9.11.0_p2-r0
9.11.0_p2-r1
9.11.0_p3-r0
9.11.0_p5-r0
9.11.0_p5-r1
9.11.1-r0
9.11.1_p1-r0
9.11.1_p2-r0
9.11.1_p2-r1
9.11.1_p2-r2
9.11.2-r0
9.11.2-r1
9.11.2-r2
9.11.2_p1-r0
9.11.2_p1-r1
9.12.0-r0
9.12.0-r1
9.12.0-r2
9.12.0-r3
9.12.1_p2-r0
9.12.2_p1-r0
9.12.2_p1-r1
9.12.3-r0
9.12.3_p1-r0
9.12.3_p1-r1
9.12.3_p4-r0
9.12.3_p4-r1
9.12.3_p4-r2
9.14.0-r0
9.14.1-r0
9.14.1-r1
9.14.4-r1
9.14.4-r2
9.14.4-r3
9.14.4-r4
9.14.7-r4
9.14.7-r5
9.14.8-r5
9.14.8-r6
9.14.8-r7
9.14.12-r0
9.16.5-r0
9.16.6-r0
9.16.7-r0
9.16.8-r0
9.16.10-r0
9.16.11-r0
9.16.11-r1
9.16.11-r2
9.16.15-r2
9.16.16-r2
9.16.17-r2
9.16.18-r2
9.16.18-r3
9.16.19-r0
9.16.20-r0
9.16.20-r1
9.16.20-r2
9.16.20-r3
9.16.20-r4
9.16.22-r4
9.16.22-r5
9.16.24-r0
9.16.25-r0
9.16.27-r0
9.16.28-r0
9.16.29-r0
9.18.3-r0
9.18.3-r1
9.18.3-r2
9.18.4-r2
9.18.4-r3
9.18.5-r0
9.18.7-r0
9.18.8-r0
9.18.9-r0
9.18.10-r0
9.18.11-r0
9.18.13-r0
9.18.13-r1
9.18.13-r2
9.18.14-r0
9.18.14-r1
9.18.14-r2
9.18.14-r3
9.18.14-r4
9.18.16-r0
9.18.17-r0
9.18.18-r0
9.18.19-r0
9.18.19-r1
9.18.21-r0
9.18.24-r0
9.18.25-r0
9.18.25-r1
9.18.27-r0
9.18.27-r1
9.18.28-r1
9.18.29-r0
9.18.31-r0
9.18.32-r0
9.18.33-r0
9.20.5-r0
9.20.6-r0
9.20.7-r0
9.20.7-r1
9.20.7-r2
9.20.7-r3
9.20.7-r4
9.20.8-r0
9.20.9-r0
9.20.10-r0