---
id: CVE-2025-40780
title: >-
  In specific circumstances, due to a weakness in the Pseudo Random Number
  Generator (PRNG) that is used, it is possible for an attacker to predict the
  source port and query ID that BIND will use.

  This issue affects BIND 9 versions 9.16.0 …
summary: >-
  In specific circumstances, due to a weakness in the Pseudo Random Number
  Generator (PRNG) that is used, it is possible for an attacker to predict the
  source port and query ID that BIND will use.

  This issue affects BIND 9 versions 9.16.0 …
severity: high
cvss: 8.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N'
cwe:
  - CWE-341
published: '2025-10-22'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40780'
references:
  - url: 'https://kb.isc.org/docs/cve-2025-40780'
    label: security-officer@isc.org
  - url: 'http://www.openwall.com/lists/oss-security/2025/10/22/1'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00466
epssPercentile: 0.3831
ingestedAt: '2026-10-08T11:31:27.547Z'
---

## Overview

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use.
This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
