BIND 9 PRNG flaw predicts source port/query ID (before 9.21.13/S1)
CVE-2025-40780 Published on October 22, 2025
Cache poisoning due to weak PRNG
In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use.
This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
Vulnerability Analysis
CVE-2025-40780 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and no impact on availability.
Weakness Type
Predictable from Observable State
A number or object is predictable based on observations that the attacker can make about the state of the system or network, such as time, process ID, etc.
Products Associated with CVE-2025-40780
stack.watch emails you whenever new vulnerabilities are published in ISC BIND or Canonical Ubuntu Linux. Just hit a watch button to start following.
Affected Versions
ISC BIND 9:- Version 9.16.0, <= 9.16.50 is affected.
- Version 9.18.0, <= 9.18.39 is affected.
- Version 9.20.0, <= 9.20.13 is affected.
- Version 9.21.0, <= 9.21.12 is affected.
- Version 9.16.8-S1, <= 9.16.50-S1 is affected.
- Version 9.18.11-S1, <= 9.18.39-S1 is affected.
- Version 9.20.9-S1, <= 9.20.13-S1 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.