CVE-2025-40777 Information
Jul 17, 2025
cve
Description
If a named caching resolver is configured with serve-stale-enable yes and with stale-answer-client-timeout set to 0 (the only allowable value other than disabled) and if the resolver in the process of resolving a query encounters a CNAME chain involving a specific combination of cached or authoritative records the daemon will abort with an assertion failure.
This issue affects BIND 9 versions 9.20.0 through 9.20.10 9.21.0 through 9.21.9 and 9.20.9-S1 through 9.20.10-S1.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Reference
https://kb.isc.org/docs/cve-2025-40777
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
7.5
Related CNNVD
CNNVD-202507-2133 (Published: 2025-07-16)
Share on: