CVE-2023-7008

Source
https://cve.org/CVERecord?id=CVE-2023-7008
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-7008.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-7008
Downstream
Related
Published
2023-12-23T13:00:50.515Z
Modified
2026-05-28T04:09:22.516726557Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
Systemd-resolved: unsigned name response in signed zone is not refused when dnssec=yes
Details

A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/7xxx/CVE-2023-7008.json",
    "cna_assigner": "redhat",
    "cwe_ids": [
        "CWE-300"
    ]
}
References

Affected packages

Git / github.com/systemd/systemd

Affected ranges

Type
GIT
Repo
https://github.com/systemd/systemd
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "25"
        }
    ],
    "cpe": "cpe:2.3:a:systemd_project:systemd:25:*:*:*:*:*:*:*",
    "source": "CPE_STRING"
}

Affected versions

Other
v1
v10
v11
v12
v13
v14
v15
v16
v17
v18
v19
v2
v20
v21
v22
v23
v24
v25
v3
v4
v5
v6
v7
v8
v9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-7008.json"

Git / github.com/systemd/systemd-stable

Affected ranges

Type
GIT
Repo
https://github.com/systemd/systemd-stable
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "25"
        }
    ],
    "cpe": "cpe:2.3:a:systemd_project:systemd:25:*:*:*:*:*:*:*",
    "source": "CPE_STRING"
}

Affected versions

Other
systemd-v1
systemd-v10
systemd-v11
systemd-v12
systemd-v13
systemd-v14
systemd-v15
systemd-v16
systemd-v17
systemd-v18
systemd-v19
systemd-v2
systemd-v20
systemd-v21
systemd-v22
systemd-v23
systemd-v24
systemd-v25
systemd-v3
systemd-v4
systemd-v5
systemd-v6
systemd-v7
systemd-v8
systemd-v9
v1
v10
v11
v12
v13
v14
v15
v16
v17
v18
v19
v2
v20
v21
v22
v23
v24
v25
v3
v4
v5
v6
v7
v8
v9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-7008.json"