Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-7008

20
FAUCET Score

CVE-2023-7008 is a medium-severity vulnerability in systemd-resolved, affecting Debian Linux distributions. It allows systemd-resolved to accept unsigned DNSSEC records, enabling man-in-the-middle attackers or compromised upstream DNS resolvers to manipulate DNS records. The attack requires high complexity but could lead to high integrity impact, with no confidentiality or availability impact. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
25CPE matchmatch criteria
cpe:2.3:a:systemd_project:systemd:25:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.85%
Probability of exploitation in next 30 days
EPSS Percentile
54.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0085 is in the 12th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

microsoftpatch availablevia msrc
Product: 19661-17086Fixed in: 250.3-22
microsoftpatch availablevia msrc
Product: 19692-17084Fixed in: 255-20
microsoftpatch availablevia msrc
Product: 19667-17086Fixed in: 250.3-13
microsoftpatch availablevia msrc
Product: azl3 systemd 255-21 on Azure Linux 3.0Fixed in: 255-20
microsoftpatch availablevia msrc
Product: cbl2 systemd-bootstrap 250.3-13 on CBL Mariner 2.0Fixed in: 250.3-13
microsoftpatch availablevia msrc
Product: azl3 systemd-bootstrap 250.3-18 on Azure Linux 3.0Fixed in: 250.3-18
microsoftpatch availablevia msrc
Product: cbl2 systemd 250.3-22 on CBL Mariner 2.0Fixed in: 250.3-22
microsoftpatch availablevia msrc
Product: azl3 systemd 255-20 on Azure Linux 3.0Fixed in: 255-20
microsoftpatch availablevia msrc
Product: 19687-17084Fixed in: 250.3-18
microsoftpatch availablevia msrc
Product: 18413-17084Fixed in: 255-20
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: systemd-0:252-32.el9_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: systemd-0:239-82.el8
View patch
ubuntupatch availablevia ubuntu_usn
Product: systemd (questing)Fixed in: 257.9-0ubuntu2.5
ubuntupatch availablevia ubuntu_usn
Product: systemd (jammy)Fixed in: 249.11-0ubuntu3.21
ubuntupatch availablevia ubuntu_usn
Product: systemd (noble)Fixed in: 255.4-1ubuntu8.16
redhatvendor investigatingvia nvd_reference
View patch

Vendor Advisories (3)

ubuntuUSN-8402-1

systemd vulnerabilities

Jun 8, 2026
microsoft2023-Dec/CVE-2023-7008Moderate

Systemd-resolved: unsigned name response in signed zone is not refused when dnssec=yes

Dec 12, 2023
redhatCVE-2023-7008Moderate

systemd-resolved: Unsigned name response in signed zone is not refused when DNSSEC=yes

Dec 8, 2022

References

lists.debian.org / debian-lts-announce/2024/09/msg00001.html
lists.fedoraproject.org / archives/list/[email protected]/message/4GMDEG5PKONWNHOEYSUDRT6JEOISRMN2
lists.fedoraproject.org / archives/list/[email protected]/message/QHNBXGKJWISJETTTDTZKTBFIBJUOSLKL
security.netapp.com / advisory/ntap-20241122-0004
access.redhat.com / errata/RHSA-2024:2463
access.redhat.com / errata/RHSA-2024:3203
access.redhat.com / security/cve/CVE-2023-7008
Vendor Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
github.com / systemd/systemd/issues/25676
Issue Tracking