Log Integrity Issue in systemd by The Systemd Project
CVE-2023-31438

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
13 June 2023

What is CVE-2023-31438?

A vulnerability has been identified in systemd 253 that allows an attacker to truncate a sealed log file and then continue log sealing. This leads to a situation where the integrity check indicates no errors, even though unauthorized modifications have been made to the log. This manipulation can undermine the reliability of log records, posing a risk to system integrity and incident response efforts. Despite allegations regarding the security implications of this issue, the vendor has reportedly denied it being a security vulnerability. Users of systemd should remain vigilant and consider monitoring for updates or patches related to this issue.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.