{"id":"CVE-2025-40775","details":"When an incoming DNS protocol message includes a Transaction Signature (TSIG), BIND always checks it.  If the TSIG contains an invalid value in the algorithm field, BIND immediately aborts with an assertion failure.\nThis issue affects BIND 9 versions 9.20.0 through 9.20.8 and 9.21.0 through 9.21.7.","modified":"2026-04-10T05:26:26.325100Z","published":"2025-05-21T13:16:02Z","related":["SUSE-SU-2025:01787-1","openSUSE-SU-2025:15156-1"],"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20250523-0001/"},{"type":"WEB","url":"https://kb.isc.org/docs/cve-2025-40775"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/05/21/1"}],"schema_version":"1.7.5"}