A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Systemd | Systemd_project | 25 (including) | 25 (including) |
Red Hat Enterprise Linux 8 | RedHat | systemd-0:239-82.el8 | * |
Red Hat Enterprise Linux 9 | RedHat | systemd-0:252-32.el9_4 | * |
Red Hat Enterprise Linux 9 | RedHat | systemd-0:252-32.el9_4 | * |
Systemd | Ubuntu | bionic | * |
Systemd | Ubuntu | devel | * |
Systemd | Ubuntu | focal | * |
Systemd | Ubuntu | jammy | * |
Systemd | Ubuntu | lunar | * |
Systemd | Ubuntu | mantic | * |
Systemd | Ubuntu | noble | * |
Systemd | Ubuntu | oracular | * |
Systemd | Ubuntu | trusty | * |
Systemd | Ubuntu | trusty/esm | * |
Systemd | Ubuntu | xenial | * |