RHSA-2025:21740HighCVSS 8.6

Red Hat Security Advisory: bind security update

Published
November 19, 2025
Last Modified
September 1, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2021-25220 — bind: DNS forwarders - cache poisoning vulnerability CVE-2025-40778 — bind: Cache poisoning attacks with unsolicited RRs

🎯 Affected products136

  • Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • bind-32:9.11.26-4.el8_4.8.src as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • bind-32:9.11.26-4.el8_4.8.src as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • bind-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • bind-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • bind-chroot-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • bind-chroot-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • bind-debuginfo-32:9.11.26-4.el8_4.8.i686 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • bind-debuginfo-32:9.11.26-4.el8_4.8.i686 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • bind-debuginfo-32:9.11.26-4.el8_4.8.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • bind-debuginfo-32:9.11.26-4.el8_4.8.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • bind-debuginfo-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • bind-debuginfo-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • bind-debuginfo-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • bind-debuginfo-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • bind-debugsource-32:9.11.26-4.el8_4.8.i686 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • bind-debugsource-32:9.11.26-4.el8_4.8.i686 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • bind-debugsource-32:9.11.26-4.el8_4.8.i686 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • bind-debugsource-32:9.11.26-4.el8_4.8.i686 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • bind-debugsource-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • bind-debugsource-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • bind-debugsource-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v.8.4)
  • bind-debugsource-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS EXTENSION (v.8.4)
  • bind-devel-32:9.11.26-4.el8_4.8.i686 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • bind-devel-32:9.11.26-4.el8_4.8.i686 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • bind-devel-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.4)
  • bind-devel-32:9.11.26-4.el8_4.8.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4)
  • +106 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: If applicable, modify your configuration to either remove all forwarding or all possibility of recursion. Depending on your use case, it may be possible to use other zone types to replace forward zones. Workaround: While it is not possible to eliminate risk from this vulnerability, there are several options for reducing the risk. These include restricting recursive queries to trusted or internal networks only, and apply rate limiting or firewall rules to prevent excessive or repetitive requests. Enabling DNSSEC validation helps reject forged records, while isolating recursive resolvers from authoritative servers limits the impact of potential cache poisoning. Active monitoring of CPU usage, query volume, and cache anomalies can provide early warning of abuse or attacks.

🔗 References (5)