RHSA-2025:22168HighCVSS 8.6

Red Hat Security Advisory: bind9.16 security update

Published
November 26, 2025
Last Modified
September 1, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2021-25220 — bind: DNS forwarders - cache poisoning vulnerability CVE-2025-40778 — bind: Cache poisoning attacks with unsolicited RRs CVE-2025-40780 — bind: Cache poisoning due to weak PRNG

🎯 Affected products63

  • Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • Red Hat Enterprise Linux AppStream TUS (v.8.6)
  • bind9.16-32:9.16.23-0.7.el8_6.9.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-32:9.16.23-0.7.el8_6.9.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-32:9.16.23-0.7.el8_6.9.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-32:9.16.23-0.7.el8_6.9.src as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • bind9.16-32:9.16.23-0.7.el8_6.9.src as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-32:9.16.23-0.7.el8_6.9.src as a component of Red Hat Enterprise Linux AppStream TUS (v.8.6)
  • bind9.16-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • bind9.16-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream TUS (v.8.6)
  • bind9.16-chroot-32:9.16.23-0.7.el8_6.9.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-chroot-32:9.16.23-0.7.el8_6.9.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-chroot-32:9.16.23-0.7.el8_6.9.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-chroot-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • bind9.16-chroot-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-chroot-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream TUS (v.8.6)
  • bind9.16-debuginfo-32:9.16.23-0.7.el8_6.9.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-debuginfo-32:9.16.23-0.7.el8_6.9.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-debuginfo-32:9.16.23-0.7.el8_6.9.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-debuginfo-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • bind9.16-debuginfo-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-debuginfo-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream TUS (v.8.6)
  • bind9.16-debugsource-32:9.16.23-0.7.el8_6.9.aarch64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-debugsource-32:9.16.23-0.7.el8_6.9.ppc64le as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-debugsource-32:9.16.23-0.7.el8_6.9.s390x as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-debugsource-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream AUS (v.8.6)
  • bind9.16-debugsource-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream E4S (v.8.6)
  • bind9.16-debugsource-32:9.16.23-0.7.el8_6.9.x86_64 as a component of Red Hat Enterprise Linux AppStream TUS (v.8.6)
  • +33 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: If applicable, modify your configuration to either remove all forwarding or all possibility of recursion. Depending on your use case, it may be possible to use other zone types to replace forward zones. Workaround: While it is not possible to eliminate risk from this vulnerability, there are several options for reducing the risk. These include restricting recursive queries to trusted or internal networks only, and apply rate limiting or firewall rules to prevent excessive or repetitive requests. Enabling DNSSEC validation helps reject forged records, while isolating recursive resolvers from authoritative servers limits the impact of potential cache poisoning. Active monitoring of CPU usage, query volume, and cache anomalies can provide early warning of abuse or attacks. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. To reduce risk, restrict recursive queries to trusted or internal networks only, and apply rate limiting or firewall rules to prevent excessive or repetitive requests. Enabling DNSSEC validation helps reject forged records, while isolating recursive resolvers from authoritative servers limits the impact of potential cache poisoning. Active monitoring of CPU usage, query volume, and cache anomalies can provide early warning of abuse or attacks.

🔗 References (6)