ELA-1678-1 bind9 security update

cache poisoning

2026-04-09
Packagebind9
Version1:9.11.37+git20260204.fcafb2d+dfsg-0~deb10u1 (buster)
Related CVEs CVE-2025-40778


bind9 a popular name server was affected by a vulnerability.

Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache (cache poisoning).

Security fixes needed to update isc-dhcp and bind-dyndb-ldap packages.



For Debian 10 buster, these problems have been fixed in version 1:9.11.37+git20260204.fcafb2d+dfsg-0~deb10u1.

We recommend that you upgrade your bind9 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.