Re: validating the fix for CVE-2025-40778
Veaceslav Revutchi <[email protected]> Thu, 11 Dec 2025 03:34:33 -0500
| Newsgroups | gmane.network.dns.bind.user |
|---|---|
| Message-ID | <CACKHFR+0=WZr0sO=iBjDU5gfaWUcq-1=JA_8g_6OX6KZhkeSGg@mail.gmail.com> |
On Wed, Dec 10, 2025 at 5:29 AM Darren Ankney <[email protected]> wrote: > > Hi Veaceslav, > > I am able to resolve rawbank.cd using BIND 9.20.16: > Thank you, Darren, I see what you mean, using a local root does make a difference, I suppose that glue becomes more trustworthy. I was looking more for an explanation of why I was seeing different results on the three bind platforms, all supposedly patched for the CVE. The reply from Petr@ISC clarified it for me in the sense that the fix may be broken on that one system and I may need to follow-up with redhat. If I wanted to work around the poor setup at the root for ".cd" I understand I have options. -- Visit https://lists.isc.org/mailman/listinfo/bind-users to unsubscribe from this list.