CVE Details
Basic Information
| Title |
CVE-2025-40775 DNS message with invalid TSIG causes an assertion failure |
| Type |
cve |
| Published |
2025-05-21T12:35:01 |
| Last Seen |
2025-05-21T13:24:37 |
CVSS Information
| Base Score |
7.5 (HIGH) |
| Attack Vector |
NETWORK |
| Attack Complexity |
LOW |
| Privileges Required |
NONE |
| User Interaction |
NONE |
| Scope |
UNCHANGED |
| Confidentiality Impact |
NONE |
| Integrity Impact |
NONE |
| Availability Impact |
HIGH |
AI Analysis
| AI Description |
BIND, a widely used DNS server software, can be forced to abort with an assertion failure if it receives a DNS message with an invalid TSIG algorithm field. This vulnerability can be exploited by an attacker to cause a denial of service by crashing the BIND server. |
| AI Severity |
High |
| Vendor |
Internet Systems Consortium (ISC) |
| Product |
BIND |
| Affected Version |
|
Additional Information
| CVE List |
CVE-2025-40775 |
| CWE List |
CWE-232 |
| Bulletin Family |
cve |
Description
When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it. If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure….
CVSS Score Summary
Base Score: %!f(string=#) (HIGH)
View Full CVE Details