Cyber Security News

BIND 9 Vulnerabilities Expose Organizations to Cache Poisoning and DoS Attacks

Two critical vulnerabilities in the BIND 9 DNS resolver software are affecting organizations worldwide, with potential cache poisoning and denial-of-service attacks. 

The vulnerabilities, identified as CVE-2025-40776 and CVE-2025-40777, pose significant security risks to DNS infrastructure, particularly for resolvers configured with specific advanced features.

Key Takeaways
1. CVE-2025-40776 (cache poisoning) and CVE-2025-40777 (denial-of-service)  affecting BIND 9 resolvers.
2. Target-specific BIND configurations can be exploited remotely without authentication.
3. Upgrade to patched versions or disable vulnerable features.

BIND 9 Cache Poisoning Flaw (CVE-2025-40776)

The first vulnerability, CVE-2025-40776, targets BIND 9 resolvers configured with EDNS Client Subnet (ECS) options, carrying a high severity rating of 8.6 on the CVSS scale. 

This birthday attack vulnerability affects only the BIND Subscription Edition (-S) versions, including 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

The attack exploits resolvers sending ECS options to authoritative servers, compelling them to make queries that increase the probability of successful source port guessing. 

Xiang Li from AOSP Lab of Nankai University discovered this vulnerability, which bypasses original birthday cache poisoning attack mitigations. 

The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N indicates network-accessible exploitation with high integrity impact.

BIND 9 DoS Vulnerability (CVE-2025-40777)

CVE-2025-40777 presents a different threat vector, enabling denial-of-service attacks through assertion failures with a CVSS score of 7.5. 

This vulnerability affects BIND versions 9.20.0 through 9.20.10 and 9.21.0 through 9.21.9, plus corresponding Supported Preview Edition versions. 

The vulnerability triggers when resolvers are configured with serve-stale-enable yes and stale-answer-client-timeout set to 0.

Attackers can exploit specific CNAME chain combinations involving cached or authoritative records to force named daemon termination. 

The vulnerability was discovered during internal testing, with no active exploits currently identified. The CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H reflects high availability impact through remote exploitation.

CVETitleAffected ProductsCVSS 3.1 ScoreSeverity
CVE-2025-40776Birthday Attack against Resolvers supporting ECSBIND 9 Supported Preview Edition:- 9.11.3-S1 → 9.16.50-S1- 9.18.11-S1 → 9.18.37-S1- 9.20.9-S1 → 9.20.10-S18.6High
CVE-2025-40777A possible assertion failure when using the ‘stale-answer-client-timeout 0’ optionBIND 9:- 9.20.0 → 9.20.10- 9.21.0 → 9.21.9
BIND Supported Preview Edition:- 9.20.9-S1 → 9.20.10-S1
7.5High

Mitigations

ISC recommends immediate patching to resolve both vulnerabilities. 

For CVE-2025-40776, organizations should upgrade to BIND 9.18.38-S1 or 9.20.11-S1, or disable ECS by removing the ecs-zones option from named.conf. CVE-2025-40777 requires upgrading to BIND 9.20.11 or 9.21.10, with temporary workarounds including setting stale-answer-client-timeout off or stale-answer-enable no in configuration files.

These vulnerabilities highlight the critical importance of maintaining updated DNS infrastructure, as both cache poisoning and denial-of-service attacks can severely compromise organizational security posture and service availability.

Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -> Try ANY.RUN Now 

Kaaviya

Kaaviya is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago