UBUNTU-CVE-2025-40780
Dashboard / Vulnerabilities / UBUNTU-CVE-2025-40780
UBUNTU-CVE-2025-40780
Summary:
Details: In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
References: https://ubuntu.com/security/CVE-2025-40780, https://www.cve.org/CVERecord?id=CVE-2025-40780, https://ubuntu.com/security/notices/USN-7836-1, https://ubuntu.com/security/notices/USN-7836-2
Affected packages
Package
Name: bind9
Purl: pkg:deb/ubuntu/bind9?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
