<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T03:17:18.054692+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:19793</id>
    <title>ALSA-2025:19793 — Important: bind9.16 security update</title>
    <updated>2026-10-03T03:17:18.129858+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: bind9.16, AlmaLinux:8: bind9.16-chroot, AlmaLinux:8: bind9.16-devel, AlmaLinux:8: bind9.16-dnssec-utils, AlmaLinux:8: bind9.16-doc, AlmaLinux:8: bind9.16-libs, AlmaLinux:8: bind9.16-license, AlmaLinux:8: bind9.16-utils, AlmaLinux:8: python3-bind9.16</p>
<p>The Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols. BIND includes a DNS server (named); a resolver library (routines for applications to use when interfacing with DNS); and tools for verifying that the DNS server is operating correctly.</p>
<p>Security Fix(es):</p>
<p>* bind: Cache poisoning attacks with unsolicited RRs (CVE-2025-40778)
  * bind: Cache poisoning due to weak PRNG (CVE-2025-40780)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:19793"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-13637</id>
    <title>bdu:2025-13637</title>
    <updated>2026-10-03T03:17:18.129953+00:00</updated>
    <content>bdu:2025-13637</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-13637"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-40778</id>
    <title>BELL-CVE-2025-40778</title>
    <updated>2026-10-03T03:17:18.129972+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: bind, Alpaquita:25: bind, Alpaquita:stream: bind</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-40778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0913</id>
    <title>certfr-2025-avi-0913 — De multiples vulnérabilités ont été découvertes dans ISC BIND. Elles permettent à un attaquant de provoquer un déni de…</title>
    <updated>2026-10-03T03:17:18.129995+00:00</updated>
    <content>certfr-2025-avi-0913</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0913"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-26736</id>
    <title>cnvd-2025-26736</title>
    <updated>2026-10-03T03:17:18.130012+00:00</updated>
    <content>cnvd-2025-26736</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-26736"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-271438</id>
    <title>EUVD-2026-271438</title>
    <updated>2026-10-03T03:17:18.130025+00:00</updated>
    <content>EUVD-2026-271438</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-271438"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-40778</id>
    <title>fkie_cve-2025-40778</title>
    <updated>2026-10-03T03:17:18.130035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-40778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xmqp-6cj2-2hh3</id>
    <title>GHSA-xmqp-6cj2-2hh3</title>
    <updated>2026-10-03T03:17:18.130058+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xmqp-6cj2-2hh3"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-40778</id>
    <title>msrc_CVE-2025-40778 — Cache poisoning attacks with unsolicited RRs</title>
    <updated>2026-10-03T03:17:18.130073+00:00</updated>
    <content>msrc_CVE-2025-40778</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-40778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2653</id>
    <title>OESA-2025-2653 — bind security update</title>
    <updated>2026-10-03T03:17:18.130090+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:22.03-LTS-SP3: bind</p>
<p>Berkeley Internet Name Domain (BIND) is an implementation of the Domain Name System (DNS) protocols and provides an openly redistributable reference implementation of the major components of the Domain Name System. This package includes the components to operate a DNS server.

Security Fix(es):</p>
<p>Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.(CVE-2025-40778)</p>
<p>In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.(CVE-2025-40780)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2653"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15659-1</id>
    <title>openSUSE-SU-2025:15659-1 — bind-9.20.15-1.1 on GA media</title>
    <updated>2026-10-03T03:17:18.130118+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bind-9.20.15-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15659-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:19912</id>
    <title>RHSA-2025:19912 — Red Hat Security Advisory: bind security update</title>
    <updated>2026-10-03T03:17:18.130136+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>bind: Resource exhaustion via malformed DNSKEY handling bind: Cache poisoning attacks with unsolicited RRs bind: Cache poisoning due to weak PRNG</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:19912"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:3976-1</id>
    <title>SUSE-SU-2025:3976-1 — Security update for bind</title>
    <updated>2026-10-03T03:17:18.130157+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for bind</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:3976-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40778</id>
    <title>UBUNTU-CVE-2025-40778</title>
    <updated>2026-10-03T03:17:18.130171+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: bind9, Ubuntu:Pro:16.04:LTS: bind9, Ubuntu:Pro:18.04:LTS: bind9, Ubuntu:18.04:LTS: isc-dhcp, Ubuntu:Pro:20.04:LTS: bind9, Ubuntu:20.04:LTS: bind9-libs, Ubuntu:22.04:LTS: bind9, Ubuntu:22.04:LTS: bind9-libs, Ubuntu:24.04:LTS: bind9, Ubuntu:24.04:LTS: isc-dhcp and 4 more</p>
<p>Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-40778"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2392</id>
    <title>WID-SEC-W-2025-2392 — Internet Systems Consortium BIND: Mehrere Schwachstellen</title>
    <updated>2026-10-03T03:17:18.130210+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Internet Systems Consortium BIND ausnutzen, um Dateien zu manipulieren und um einen Denial-of-Service-Zustand zu verursachen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2392"/>
  </entry>
</feed>
