CVE-2023-31438: Medium severity Systemd Project Systemd vulnerability
DISPUTED An issue was discovered in systemd 253. An attacker can truncate a sealed log file and then resume log sealing such that checking the integrity shows no error, despite modifications. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID of the vulnerability?
The CVE ID of this vulnerability is CVE-2023-31438.
What is the severity of CVE-2023-31438?
The severity of CVE-2023-31438 is medium with a CVSS score of 5.3.
What software is affected by CVE-2023-31438?
The software affected by CVE-2023-31438 is Systemd version 253.
How can an attacker exploit CVE-2023-31438?
An attacker can truncate a sealed log file and then resume log sealing to hide modifications.
Are there any references for CVE-2023-31438?
Yes, you can find references for CVE-2023-31438 at the following links: [link1](https://github.com/kastel-security/Journald), [link2](https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf), [link3](https://github.com/systemd/systemd/releases).