Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-61972.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-61972
Upstream
Published
2025-05-21T13:16:02Z
Modified
2026-04-21T04:31:53.600650Z
Summary
CVE-2025-40775 affecting package bind for versions less than 9.20.9-1
Details

When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.

References

Affected packages

Azure Linux:3 / bind

Package

Name
bind
Purl
pkg:rpm/azure-linux/bind

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.20.9-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-61972.json"