CVE-2023-7008

The systemd-resolved DNSSEC flaw: accepting unsigned records it was configured to reject

systemd-resolved could accept DNS records that had not been signed, in a configuration where it was supposed to require signatures. The protection was on, and it was not protecting.

systemdNot in CISA’s Known Exploited catalogueEPSS 0.85% chance of an attempt in 30 daysCVSS 5.9CWE-300CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

A fixed package version is available on 6 of the releases below. Each row names the version, and the section below it says when this does not apply to you at all.

One read-only command. No account, no agent, nothing changed.

What it actually is

With DNSSEC validation enabled, systemd-resolved did not reject records that arrived without a valid signature in certain response shapes, so an attacker able to answer a DNS query could have a forged answer accepted.

What an attacker gets: DNS responses under the attacker's control, for whoever can answer the query first. That is the starting point for redirecting traffic, issuing certificates, or intercepting mail.

When it applies to you, and when it does not

An old package version and a real exposure are different things. These are the conditions this one needs.

  • It needs systemd-resolved to be the resolver in use, which is the default on Ubuntu and increasingly elsewhere, and DNSSEC validation to be enabled.
  • It needs an attacker positioned to answer DNS, which usually means the local network or a compromised upstream resolver.
  • A server using a different resolver, or one with DNSSEC never enabled, was not relying on the protection that failed.

Check your own server

Read-only, changes nothing
resolvectl status 2>/dev/null | grep -iE 'dnssec|current dns' | head -5

Shows whether systemd-resolved is in use and whether DNSSEC is on. If it says DNSSEC=no, the setting that failed was not in force.

Fixed package version, per distribution

From each distribution’s own advisory data, asked per release. A version here is the package version that carries the fix on that release, not the upstream release number.

ReleaseSource packageStateFixed in
Ubuntu 22.04 LTSsystemdFixed249.11-0ubuntu3.21
Ubuntu 24.04 LTSsystemdFixed255.4-1ubuntu8.16
Debian 12 (bookworm)systemdFixed252.21-1~deb12u1
Debian 13 (trixie)systemdFixed255.1-3
Rocky Linux 9systemdFixed0:252-32.el9_4
AlmaLinux 9systemdFixed252-32.el9_4.alma.1

Install the fix with apt update && apt install --only-upgrade systemd systemd-resolved on Debian and Ubuntu, or dnf update systemd systemd-resolved on Rocky Linux and AlmaLinux. Restart whatever was using it afterwards: a patched file on disk is not a patched process in memory.

What SecAI has recorded about it

A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.

Recorded from nvd. Its weakness class is CWE-300, from NVD.

Read next

Check whether this vulnerability affects your Linux server

One read-only command, no account and no agent. It reads the installed package versions on your server and tells you which advisories apply to them, CVE-2023-7008 included. It changes nothing.