Insufficient verification of data authenticity in systemd - CVE-2023-7008

 

Insufficient verification of data authenticity in systemd - CVE-2023-7008

Published: January 22, 2024


Vulnerability identifier: #VU85658
CSH Severity: Medium
CVSS v4 BT: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2023-7008
CWE-ID: CWE-345
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a MitM attack.

The vulnerability exists due to systemd-resolved accepts records of DNSSEC-signed domains even when they have no signature. A remote attacker can perform MitM attack.


Affected software

systemd
systemd-journal-remote
systemd-devel
systemd-libs
systemd-pam
systemd-tests
systemd-udev
systemd-container
systemd (Red Hat package)
systemd-udev-compat
systemd-debugsource
systemd-resolved
systemd-debuginfo
systemd-nspawn
systemd-networkd
systemd-timesyncd
systemd-help
systemd-journal-remote-debuginfo
nss-myhostname-32bit-debuginfo
libsystemd0-32bit
systemd-32bit
systemd-32bit-debuginfo
libudev1-32bit
libsystemd0-32bit-debuginfo
libudev1-32bit-debuginfo
nss-myhostname-32bit
systemd-lang
libudev1-64bit
libudev1-64bit-debuginfo
systemd-64bit-debuginfo
libsystemd0-64bit
nss-myhostname-64bit
nss-myhostname-64bit-debuginfo
systemd-64bit
libsystemd0-64bit-debuginfo
systemd-mini-devel
systemd-container-debuginfo
systemd-network
udev-mini-debuginfo
libsystemd0-debuginfo
systemd-testsuite-debuginfo
nss-myhostname
systemd-mini-container-debuginfo
systemd-doc
libudev1
systemd-mini-sysvinit
nss-myhostname-debuginfo
systemd-mini
systemd-network-debuginfo
systemd-sysvinit
nss-systemd-debuginfo
systemd-mini-doc
systemd-mini-debuginfo
udev-debuginfo
systemd-portable-debuginfo
udev-mini
libudev1-debuginfo
nss-systemd
systemd-coredump-debuginfo
systemd-portable
systemd-experimental
libudev-mini1-debuginfo
libsystemd0
systemd-experimental-debuginfo
systemd-mini-debugsource
systemd-mini-container
libsystemd0-mini-debuginfo
udev
systemd-coredump
libudev-mini1
systemd-testsuite
libsystemd0-mini
Amazon Linux AMI
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Enterprise Micro
openSUSE Leap Micro
Red Hat Enterprise Linux for Power, little endian
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for ARM 64
Basesystem Module
SUSE Package Hub 15
openSUSE Leap
openEuler
Fedora
Voice Gateway
IBM MQ Operator
Migration Toolkit for Runtimes
Service Interconnect
Ansible Automation Platform
Custom Metrics Autoscaler Operator for Red Hat OpenShift
Red Hat OpenShift distributed tracing (RHOSDT)
IBM Cloud Transformation Advisor
App Connect Enterprise Certified Container
Red Hat Migration Toolkit for Applications
Red Hat OpenStack
Cloud Pak for Network Automation
Guardium Data Security Center (GDSC)
webMethods Managed File Transfer
IBM Qradar SIEM
Juniper Secure Analytics (JSA)
Juniper Junos Space
OpenShift API for Data Protection (OADP)
Network Observability plugin for the Openshift Console
Red Hat OpenShift GitOps
Red Hat OpenShift Serverless
OpenShift Service Mesh
OpenShift Virtualization
OpenShift Container Platform for Windows Containers
Red Hat OpenShift Container Platform
Red Hat Ceph Storage
Red Hat Single Sign-On

How to mitigate CVE-2023-7008

Install updates from vendor's website.

Voice Gateway - update to 1.0.8.12
IBM MQ Operator - addressed in versions 2.0.23, 3.2.0
Cloud Pak for Network Automation - update to 2.7.4
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 9 IF02
Juniper Secure Analytics (JSA) - update to 7.5.0 UP9 IF02
Juniper Junos Space - update to 24.1R2
Migration Toolkit for Runtimes - update to 1.2.6
OpenShift API for Data Protection (OADP) - update to 1.3.2
Service Interconnect - update to 1.5.4
Network Observability plugin for the Openshift Console - update to 1.6.0
Red Hat OpenShift GitOps - addressed in versions 1.10.6, 1.11.5, 1.12.3
Red Hat OpenShift Serverless - update to 1.33.0
Ansible Automation Platform - update to 2.4
OpenShift Service Mesh - addressed in versions 2.4.8, 2.5.2
Custom Metrics Autoscaler Operator for Red Hat OpenShift - update to 2.12.1-394
Red Hat OpenShift distributed tracing (RHOSDT) - update to 3.2.0
IBM Cloud Transformation Advisor - update to 3.10.0
Red Hat OpenShift Container Platform - update to 4.12.58
OpenShift Virtualization - update to 4.14.6
App Connect Enterprise Certified Container - addressed in versions 5.0.19, 12.2.0
Red Hat Ceph Storage - update to 5.3
Red Hat Migration Toolkit for Applications - addressed in versions 6.2.3, 7.0.3
Red Hat Single Sign-On - update to 7.6.9
OpenShift Container Platform for Windows Containers - update to 10.15.3
Red Hat OpenStack - update to 17.1
systemd-journal-remote - update to 239-78.0.7
systemd-devel - update to 239-78.0.7
systemd-libs - update to 239-78.0.7
systemd-pam - update to 239-78.0.7
systemd-tests - update to 239-78.0.7
systemd-udev - update to 239-78.0.7
systemd-container - update to 239-78.0.7
systemd - update to 239-78.0.7
systemd (Red Hat package) - addressed in versions 239-82.el8, 252-32.el9_4
systemd - addressed in versions 243-71, 243-81
systemd-journal-remote - addressed in versions 243-71, 243-81
systemd-udev-compat - addressed in versions 243-71, 243-81
systemd-pam - update to 243-71
systemd-devel - addressed in versions 243-71, 243-81
systemd-debugsource - addressed in versions 243-71, 243-81
systemd-resolved - update to 243-71
systemd-debuginfo - addressed in versions 243-71, 243-81
systemd-nspawn - update to 243-71
systemd-container - addressed in versions 243-71, 243-81
systemd-networkd - update to 243-71
systemd-timesyncd - update to 243-71
systemd-libs - addressed in versions 243-71, 243-81
systemd-help - addressed in versions 243-71, 243-81
systemd-udev - addressed in versions 243-71, 243-81
systemd-journal-remote-debuginfo - update to 249.17-150400.8.43.1
nss-myhostname-32bit-debuginfo - update to 249.17-150400.8.43.1
libsystemd0-32bit - update to 249.17-150400.8.43.1
systemd-32bit - update to 249.17-150400.8.43.1
systemd-32bit-debuginfo - update to 249.17-150400.8.43.1
libudev1-32bit - update to 249.17-150400.8.43.1
libsystemd0-32bit-debuginfo - update to 249.17-150400.8.43.1
libudev1-32bit-debuginfo - update to 249.17-150400.8.43.1
nss-myhostname-32bit - update to 249.17-150400.8.43.1
systemd-lang - update to 249.17-150400.8.43.1
libudev1-64bit - update to 249.17-150400.8.43.1
libudev1-64bit-debuginfo - update to 249.17-150400.8.43.1
systemd-64bit-debuginfo - update to 249.17-150400.8.43.1
libsystemd0-64bit - update to 249.17-150400.8.43.1
nss-myhostname-64bit - update to 249.17-150400.8.43.1
nss-myhostname-64bit-debuginfo - update to 249.17-150400.8.43.1
systemd-64bit - update to 249.17-150400.8.43.1
libsystemd0-64bit-debuginfo - update to 249.17-150400.8.43.1
systemd-mini-devel - update to 249.17-150400.8.43.1
systemd-container-debuginfo - update to 249.17-150400.8.43.1
systemd-network - update to 249.17-150400.8.43.1
udev-mini-debuginfo - update to 249.17-150400.8.43.1
libsystemd0-debuginfo - update to 249.17-150400.8.43.1
systemd-testsuite-debuginfo - update to 249.17-150400.8.43.1
nss-myhostname - update to 249.17-150400.8.43.1
systemd-mini-container-debuginfo - update to 249.17-150400.8.43.1
systemd-doc - update to 249.17-150400.8.43.1
libudev1 - update to 249.17-150400.8.43.1
systemd-mini-sysvinit - update to 249.17-150400.8.43.1
systemd-devel - update to 249.17-150400.8.43.1
systemd-container - update to 249.17-150400.8.43.1
nss-myhostname-debuginfo - update to 249.17-150400.8.43.1
systemd-mini - update to 249.17-150400.8.43.1
systemd-network-debuginfo - update to 249.17-150400.8.43.1
systemd - update to 249.17-150400.8.43.1
systemd-sysvinit - update to 249.17-150400.8.43.1
nss-systemd-debuginfo - update to 249.17-150400.8.43.1
systemd-mini-doc - update to 249.17-150400.8.43.1
systemd-mini-debuginfo - update to 249.17-150400.8.43.1
udev-debuginfo - update to 249.17-150400.8.43.1
systemd-portable-debuginfo - update to 249.17-150400.8.43.1
udev-mini - update to 249.17-150400.8.43.1
libudev1-debuginfo - update to 249.17-150400.8.43.1
nss-systemd - update to 249.17-150400.8.43.1
systemd-coredump-debuginfo - update to 249.17-150400.8.43.1
systemd-portable - update to 249.17-150400.8.43.1
systemd-experimental - update to 249.17-150400.8.43.1
libudev-mini1-debuginfo - update to 249.17-150400.8.43.1
libsystemd0 - update to 249.17-150400.8.43.1
systemd-experimental-debuginfo - update to 249.17-150400.8.43.1
systemd-mini-debugsource - update to 249.17-150400.8.43.1
systemd-mini-container - update to 249.17-150400.8.43.1
libsystemd0-mini-debuginfo - update to 249.17-150400.8.43.1
udev - update to 249.17-150400.8.43.1
systemd-debugsource - update to 249.17-150400.8.43.1
systemd-debuginfo - update to 249.17-150400.8.43.1
systemd-coredump - update to 249.17-150400.8.43.1
libudev-mini1 - update to 249.17-150400.8.43.1
systemd-testsuite - update to 249.17-150400.8.43.1
systemd-journal-remote - update to 249.17-150400.8.43.1
libsystemd0-mini - update to 249.17-150400.8.43.1
systemd - update to 252.16-1
systemd - addressed in versions 253.15-2.fc38, 254.8-2.fc39

External References

Related Security Bulletins