CVE-2025-40777

Published Jul 16, 2025

Last updated 17 days ago

CVSS high 7.5
Dns
Port (53)

Overview

Description
If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `disabled`), and if the resolver, in the process of resolving a query, encounters a CNAME chain involving a specific combination of cached or authoritative records, the daemon will abort with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.10, 9.21.0 through 9.21.9, and 9.20.9-S1 through 9.20.10-S1.
Source
security-officer@isc.org
NVD status
Deferred

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

security-officer@isc.org
CWE-617

Social media

Hype score
Not currently trending
  1. 🚨CVE-2025-40776: Cache Poisoning Vulnerability and CVE-2025-40777: Crash Vulnerability FOFA Query: app="ISC-BIND-DNS" Results: 15,918 FOFA: https://t.co/i03uGrqevp CVSS: 8.6 and 7.5 More Info: https://t.co/YCinE08Kj0 https://t.co/GKqAJ8nzw5

    @DarkWebInformer

    29 Jul 2025

    3811 Impressions

    4 Retweets

    27 Likes

    11 Bookmarks

    1 Reply

    0 Quotes

  2. 【メールマガジン(FROM JPRS)】最新号を掲載しました。 通常号 vol.1204「BIND 9.20.xの脆弱性(DNSサービスの停止)について(CVE-2025-40777)、他1件」など https://t.co/dMQElKLHWo

    @JPRS_official

    22 Jul 2025

    156 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. به تازگی برای BIND ورژن 9 دو آسیب پذیری خطرناک با کدهای شناسایی CVE-2025-40776 و CVE-2025-40777 منتشر شده است. آسیب پذیری اول از نوع DNS Cache Poisoning و آسیب پذیری دوم از نوع DOS می

    @AmirHossein_sec

    19 Jul 2025

    30 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. CVE-2025-40776 and CVE-2025-40777 # BIND 9 DNS resolver Cache Poisoning & dos flaw exposed >>>: https://t.co/nzWBQ5e9dl

    @cyberbivash

    19 Jul 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-40776 and CVE-2025-40777 # BIND 9 DNS resolver Cache Poisoning & dos flaw exposed >>>: https://t.co/nzWBQ5eH2T

    @cyberbivash

    19 Jul 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️⚠️ CVE-2025-40776 and CVE-2025-40777 ISC Warns of Cache Poisoning and Crash Risks in BIND 🎯16k+ Results are found on the https://t.co/pb16tGYaKe nearly year 🔗FOFA Link:https://t.co/8vbFRsWzQh FOFA Query:app="ISC-BIND-DNS" 🔖Refer:https://t.co/rhRHNZCxgN #OSINT #

    @fofabot

    18 Jul 2025

    704 Impressions

    1 Retweet

    7 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  7. BIND 9.20.xの脆弱性(DNSサービスの停止)について(CVE-2025-40777) https://t.co/wJKIiPja2J

    @vericava

    17 Jul 2025

    103 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 【注意喚起】BIND 9.20.xの脆弱性(DNSサービスの停止)について(CVE-2025-40777) - バージョンアップを強く推奨 - https://t.co/kQIUR5ukNJ

    @JPRS_official

    17 Jul 2025

    1971 Impressions

    4 Retweets

    7 Likes

    1 Bookmark

    0 Replies

    2 Quotes

  9. RHEL6〜10はNot Affected ヨシっ // "CVE-2025-40777 Moderate 5.3" https://t.co/YyMIIOhGpM

    @w4yh

    17 Jul 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2025-40777 If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `d… https://t.co/9YhKUpQVSa

    @CVEnew

    16 Jul 2025

    237 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes