Amazon Linux 2 Security Advisory: ALAS2-2025-3093
Advisory Released Date: 2025-12-08
Advisory Updated Date: 2025-12-08
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1. (CVE-2025-40778)
Affected Packages:
bind
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update bind or yum update --advisory ALAS2-2025-3093 to update your system.
aarch64:
bind-9.11.4-26.P2.amzn2.13.13.aarch64
bind-pkcs11-9.11.4-26.P2.amzn2.13.13.aarch64
bind-pkcs11-utils-9.11.4-26.P2.amzn2.13.13.aarch64
bind-pkcs11-libs-9.11.4-26.P2.amzn2.13.13.aarch64
bind-pkcs11-devel-9.11.4-26.P2.amzn2.13.13.aarch64
bind-sdb-9.11.4-26.P2.amzn2.13.13.aarch64
bind-libs-lite-9.11.4-26.P2.amzn2.13.13.aarch64
bind-libs-9.11.4-26.P2.amzn2.13.13.aarch64
bind-utils-9.11.4-26.P2.amzn2.13.13.aarch64
bind-devel-9.11.4-26.P2.amzn2.13.13.aarch64
bind-lite-devel-9.11.4-26.P2.amzn2.13.13.aarch64
bind-chroot-9.11.4-26.P2.amzn2.13.13.aarch64
bind-sdb-chroot-9.11.4-26.P2.amzn2.13.13.aarch64
bind-export-libs-9.11.4-26.P2.amzn2.13.13.aarch64
bind-export-devel-9.11.4-26.P2.amzn2.13.13.aarch64
bind-debuginfo-9.11.4-26.P2.amzn2.13.13.aarch64
i686:
bind-9.11.4-26.P2.amzn2.13.13.i686
bind-pkcs11-9.11.4-26.P2.amzn2.13.13.i686
bind-pkcs11-utils-9.11.4-26.P2.amzn2.13.13.i686
bind-pkcs11-libs-9.11.4-26.P2.amzn2.13.13.i686
bind-pkcs11-devel-9.11.4-26.P2.amzn2.13.13.i686
bind-sdb-9.11.4-26.P2.amzn2.13.13.i686
bind-libs-lite-9.11.4-26.P2.amzn2.13.13.i686
bind-libs-9.11.4-26.P2.amzn2.13.13.i686
bind-utils-9.11.4-26.P2.amzn2.13.13.i686
bind-devel-9.11.4-26.P2.amzn2.13.13.i686
bind-lite-devel-9.11.4-26.P2.amzn2.13.13.i686
bind-chroot-9.11.4-26.P2.amzn2.13.13.i686
bind-sdb-chroot-9.11.4-26.P2.amzn2.13.13.i686
bind-export-libs-9.11.4-26.P2.amzn2.13.13.i686
bind-export-devel-9.11.4-26.P2.amzn2.13.13.i686
bind-debuginfo-9.11.4-26.P2.amzn2.13.13.i686
noarch:
bind-license-9.11.4-26.P2.amzn2.13.13.noarch
src:
bind-9.11.4-26.P2.amzn2.13.13.src
x86_64:
bind-9.11.4-26.P2.amzn2.13.13.x86_64
bind-pkcs11-9.11.4-26.P2.amzn2.13.13.x86_64
bind-pkcs11-utils-9.11.4-26.P2.amzn2.13.13.x86_64
bind-pkcs11-libs-9.11.4-26.P2.amzn2.13.13.x86_64
bind-pkcs11-devel-9.11.4-26.P2.amzn2.13.13.x86_64
bind-sdb-9.11.4-26.P2.amzn2.13.13.x86_64
bind-libs-lite-9.11.4-26.P2.amzn2.13.13.x86_64
bind-libs-9.11.4-26.P2.amzn2.13.13.x86_64
bind-utils-9.11.4-26.P2.amzn2.13.13.x86_64
bind-devel-9.11.4-26.P2.amzn2.13.13.x86_64
bind-lite-devel-9.11.4-26.P2.amzn2.13.13.x86_64
bind-chroot-9.11.4-26.P2.amzn2.13.13.x86_64
bind-sdb-chroot-9.11.4-26.P2.amzn2.13.13.x86_64
bind-export-libs-9.11.4-26.P2.amzn2.13.13.x86_64
bind-export-devel-9.11.4-26.P2.amzn2.13.13.x86_64
bind-debuginfo-9.11.4-26.P2.amzn2.13.13.x86_64