#22307 closed enhancement (fixed)
bind9 bind 9.20.15
| Reported by: | Bruce Dubbs | Owned by: | Bruce Dubbs |
|---|---|---|---|
| Priority: | high | Milestone: | 13.0 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (7)
follow-up: 5 comment:1 by , 11 months ago
| Priority: | normal → high |
|---|
comment:2 by , 11 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:3 by , 11 months ago
BIND 9.20.15
Security Fixes
- [CVE-2025-8677] DNSSEC validation fails if matching but invalid DNSKEY is found.
Previously, if a matching but cryptographically invalid key was encountered during DNSSEC validation, the key was skipped and not counted towards validation failures. :iscman:
namednow treats such DNSSEC keys as hard failures and the DNSSEC validation fails immediately, instead of continuing with the next DNSKEYs in the RRset.
- [CVE-2025-40778] Address various spoofing attacks.
Previously, several issues could be exploited to poison a DNS cache with spoofed records for zones which were not DNSSEC-signed or if the resolver was configured to not do DNSSEC validation. These issues were assigned CVE-2025-40778 and have now been fixed.
As an additional layer of protection, :iscman:
namedno longer accepts DNAME records or extraneous NS records in the AUTHORITY section unless these are received via spoofing-resistant transport (TCP, UDP with DNS cookies, TSIG, or SIG(0)).
- [CVE-2025-40780] Cache-poisoning due to weak pseudo-random number generator.
It was discovered during research for an upcoming academic paper that a xoshiro128\*\* internal state can be recovered by an external 3rd party, allowing the prediction of UDP ports and DNS IDs in outgoing queries. This could lead to an attacker spoofing the DNS answers with great efficiency and poisoning the DNS cache.
The internal random generator has been changed to a cryptographically secure pseudo-random generator.
New Features
- Add dnssec-policy keys configuration check to named-checkconf.
A new option
-kis added tonamed-checkconfthat allows checking thednssec-policykeysconfiguration against the configured key stores. If the found key files are not in sync with the givendnssec-policy, the check will fail.
This is useful to run before migrating to
dnssec-policy.
Feature Changes
- Minor refactor of dst code.
Convert the defines to enums. Initialize the tags more explicitly and less ugly.
Bug Fixes
- Use signer name when disabling DNSSEC algorithms.
disable-algorithmscould cause DNSSEC validation failures when the parent zone was signed with the algorithms that were being disabled for the child zone. This has been fixed;disable-algorithmsnow works on a whole-of-zone basis.
If the zone's name is at or below the
disable-algorithmsname the algorithm is disabled for that zone, using deepest match when there are multipledisable-algorithmsclauses.
- Rndc sign during ZSK rollover will now replace signatures.
When performing a ZSK rollover, if the new DNSKEY is omnipresent, the :option:
rndc signcommand now signs the zone completely with the successor key, replacing all zone signatures from the predecessor key with new ones.
- Missing DNSSEC information when CD bit is set in query.
The RRSIGs for glue records were not being cached correctly for CD=1 queries. This has been fixed.
- Preserve cache when reload fails and reload the server again.
Fixes an issue where failing to reconfigure/reload the server would prevent to preserved the views caches on the subsequent server reconfiguration/reload.
- Check plugin config before registering.
In
named_config_parsefile(), when checking the validity ofnamed.conf, the checking of plugin correctness was deliberately postponed until the plugin is loaded and registered. However, the checking was never actually done: theplugin_register()implementation was called, butplugin_check()was not.
ns_plugin_register()(used bynamed) now calls the check function before the register function, and aborts if either one fails.ns_plugin_check()(used bynamed-checkconf) calls only the check function.
comment:5 by , 11 months ago
Replying to Bruce Dubbs:
Fixes 3 CVE's (all rated high):
- CVE-2025-8677: Resource exhaustion via malformed DNSKEY handling
- CVE-2025-40778: Cache poisoning attacks with unsolicited RRs
- CVE-2025-40780: Cache poisoning due to weak PRNG
It's unclear right now if bind utilities are affected
The good news so far is that it appears the utilities are unaffected, this seems to just affect the server components.

It's unclear right now if bind utilities are affected