HomeDefectsLIN1021-19248
Fixed

LIN1021-19248 : Security Advisory - bind - CVE-2025-40780

Created: Oct 23, 2025    Updated: Jun 8, 2026
Resolved Date: Jun 8, 2026
Found In Version: 10.21.20.1
Fix Version: 10.21.20.27
Severity: Standard
Applicable for: Wind River Linux LTS 21
Component/s: Userspace

Description

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use.[EOL]This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

CVEs