Unrated severityNVD Advisory· Published Dec 23, 2023· Updated Nov 6, 2025
Systemd-resolved: unsigned name response in signed zone is not refused when dnssec=yes
CVE-2023-7008
Description
A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
Affected products
24- Red Hat/Cryostat 2v5cpe:/a:redhat:cryostat:2
cpe:/a:redhat:enterprise_linux:9::crb+ 1 more
- cpe:/a:redhat:enterprise_linux:9::crbrange: 0:252-32.el9_4
- cpe:/o:redhat:enterprise_linux:8::baseosrange: 0:239-82.el8
- osv-coords21 versionspkg:rpm/almalinux/rhel-net-naming-sysattrspkg:rpm/almalinux/systemdpkg:rpm/almalinux/systemd-boot-unsignedpkg:rpm/almalinux/systemd-containerpkg:rpm/almalinux/systemd-develpkg:rpm/almalinux/systemd-journal-remotepkg:rpm/almalinux/systemd-libspkg:rpm/almalinux/systemd-oomdpkg:rpm/almalinux/systemd-pampkg:rpm/almalinux/systemd-resolvedpkg:rpm/almalinux/systemd-rpm-macrospkg:rpm/almalinux/systemd-testspkg:rpm/almalinux/systemd-udevpkg:rpm/opensuse/systemd&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/systemd&distro=openSUSE%20Leap%20Micro%205.5pkg:rpm/opensuse/systemd&distro=openSUSE%20Tumbleweedpkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/systemd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5
< 252-32.el9_4.alma.1+ 20 more
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 239-82.el8
- (no CPE)range: < 252-32.el9_4.alma.1
- (no CPE)range: < 249.17-150400.8.43.1
- (no CPE)range: < 249.17-150400.8.43.1
- (no CPE)range: < 254.8-4.1
- (no CPE)range: < 249.17-150400.8.43.1
- (no CPE)range: < 249.17-150400.8.43.1
- (no CPE)range: < 249.17-150400.8.43.1
- (no CPE)range: < 249.17-150400.8.43.1
- (no CPE)range: < 249.17-150400.8.43.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- access.redhat.com/errata/RHSA-2024:2463mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/errata/RHSA-2024:3203mitrevendor-advisoryx_refsource_REDHAT
- access.redhat.com/security/cve/CVE-2023-7008mitrevdb-entryx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitreissue-trackingx_refsource_REDHAT
- bugzilla.redhat.com/show_bug.cgimitre
- github.com/systemd/systemd/issues/25676mitre
News mentions
0No linked articles in our index yet.