Red Hat Security Advisory: bind security update
🔗 CVE IDs covered (2)
📋 Description
CVE-2021-25220 — bind: DNS forwarders - cache poisoning vulnerability CVE-2025-40778 — bind: Cache poisoning attacks with unsolicited RRs
🎯 Affected products31
- Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-32:9.8.2-0.68.rc1.el6_10.17.i686 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-32:9.8.2-0.68.rc1.el6_10.17.s390x as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-32:9.8.2-0.68.rc1.el6_10.17.src as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-32:9.8.2-0.68.rc1.el6_10.17.x86_64 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-chroot-32:9.8.2-0.68.rc1.el6_10.17.i686 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-chroot-32:9.8.2-0.68.rc1.el6_10.17.s390x as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-chroot-32:9.8.2-0.68.rc1.el6_10.17.x86_64 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-debuginfo-32:9.8.2-0.68.rc1.el6_10.17.i686 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-debuginfo-32:9.8.2-0.68.rc1.el6_10.17.i686 as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-debuginfo-32:9.8.2-0.68.rc1.el6_10.17.s390 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-debuginfo-32:9.8.2-0.68.rc1.el6_10.17.s390 as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-debuginfo-32:9.8.2-0.68.rc1.el6_10.17.s390x as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-debuginfo-32:9.8.2-0.68.rc1.el6_10.17.s390x as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-debuginfo-32:9.8.2-0.68.rc1.el6_10.17.x86_64 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-debuginfo-32:9.8.2-0.68.rc1.el6_10.17.x86_64 as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-devel-32:9.8.2-0.68.rc1.el6_10.17.i686 as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-devel-32:9.8.2-0.68.rc1.el6_10.17.s390 as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-devel-32:9.8.2-0.68.rc1.el6_10.17.s390x as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-devel-32:9.8.2-0.68.rc1.el6_10.17.x86_64 as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-libs-32:9.8.2-0.68.rc1.el6_10.17.i686 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-libs-32:9.8.2-0.68.rc1.el6_10.17.s390 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-libs-32:9.8.2-0.68.rc1.el6_10.17.s390x as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-libs-32:9.8.2-0.68.rc1.el6_10.17.x86_64 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-sdb-32:9.8.2-0.68.rc1.el6_10.17.i686 as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-sdb-32:9.8.2-0.68.rc1.el6_10.17.s390x as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-sdb-32:9.8.2-0.68.rc1.el6_10.17.x86_64 as a component of Red Hat Enterprise Linux Server Optional -EXTENSION (v. 6 ELS -EXTENSION)
- bind-utils-32:9.8.2-0.68.rc1.el6_10.17.i686 as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- bind-utils-32:9.8.2-0.68.rc1.el6_10.17.s390x as a component of Red Hat Enterprise Linux Server -EXTENSION(v. 6 ELS-EXTENSION)
- +1 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: If applicable, modify your configuration to either remove all forwarding or all possibility of recursion. Depending on your use case, it may be possible to use other zone types to replace forward zones. Workaround: While it is not possible to eliminate risk from this vulnerability, there are several options for reducing the risk. These include restricting recursive queries to trusted or internal networks only, and apply rate limiting or firewall rules to prevent excessive or repetitive requests. Enabling DNSSEC validation helps reject forged records, while isolating recursive resolvers from authoritative servers limits the impact of potential cache poisoning. Active monitoring of CPU usage, query volume, and cache anomalies can provide early warning of abuse or attacks.
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2025:23414
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2064512
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405827
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23414.json