This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to the patched release most closely related to your current version of BIND 9: 9.20.9 or 9.21.8.
Vendor Workaround
No workarounds known.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-16006 | When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7. |
Ubuntu USN |
USN-7526-1 | Bind vulnerability |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 23 May 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 23 May 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-617 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 21 May 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 21 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 21 May 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7. | |
| Title | DNS message with invalid TSIG causes an assertion failure | |
| Weaknesses | CWE-232 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: isc
Published:
Updated: 2025-05-23T13:11:08.588Z
Reserved: 2025-04-16T08:44:49.856Z
Link: CVE-2025-40775
Updated: 2025-05-23T13:11:08.588Z
Status : Deferred
Published: 2025-05-21T13:16:02.623
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-40775
OpenCVE Enrichment
Updated: 2025-06-23T19:31:59Z
EUVD
Ubuntu USN