CVE-2025-40775
When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 15.22%
- CWE
- CWE-232
- Published
- 2025-05-21
- Last modified
- 2026-03-12
Affected products
- ISC BIND 9
- ISC BIND 9
Weakness type
Related vulnerabilities
- CVE-2026-21689 — iccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp
- CVE-2025-20314 — A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15...
- CVE-2025-20192 — A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE...
- CVE-2023-39915 — Crashes on parsing certain invalid RPKI objects
- CVE-2023-39914 — BER/CER/DER decoder panics on invalid input
- CVE-2023-36848 — Junos OS: MX Series: The FPC will crash on receiving a malformed CFM packet
- CVE-2023-2968 — Undefined variable usage in npm package "proxy" leads to remote denial of service
- CVE-2022-22213 — Junos OS and Junos OS Evolved: Denial of Service (DoS) vulnerability in RPD upon receipt of specific BGP update