On 21 May 2025 we (Internet Systems Consortium) disclosed one vulnerability 
affecting our BIND 9 software:

- CVE-2025-40775:       DNS message with invalid TSIG causes an assertion 
failure https://kb.isc.org/docs/cve-2025-40775

New versions of BIND 9 are available from https://www.isc.org/downloads

Operators and package maintainers who prefer to apply patches selectively can find 
individual vulnerability-specific patches in the "patches" subdirectory of each 
published release directory:

- https://downloads.isc.org/isc/bind9/9.20.9/patches/
- https://downloads.isc.org/isc/bind9/9.21.8/patches/

With the public announcement of these vulnerabilities, the embargo period is 
ended and any updated software packages that have been prepared may be released.

--
Nicki Křížek (they/them)

Attachment: OpenPGP_0x01623B9B652A20A7.asc
Description: OpenPGP public key

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to