So, there is a possible solution for the Kaminsky's bug and it cames as an one-character patch.
Doing the record Authoritative nameserver on cache prevails from the new one spoofed by the attacker makes the time window for the succeed to be just until the real NS Answer arrives, basically almost impossible, one shot or two depending the bandwidth.
Personally i don´t see why it's shouldn't be like this but the question is, does RFC mention how should the behavior be? Perhaps the all world miss the point of the real problem. Random src ports only makes the attack less probably with the increase of 32 bits guesses, this patch really fix it.