{"id":"ECHO-9070-2f4f-ebc3","summary":"The CVE is disputed by upstream. It's part of 3 similar cve's, which are disputed by this article:\nhttps://github.com/kastel-security/Journald/blob/main/journald-publication.pdf\nThe guy who wrote the article also provides patches, 2 of them are in upstream, 3rd one only on his site.\nOne of the patches does not completely solve it's cve (CVE-2023-31438). We should consider this not applicable\nin the meantime and come back to it later.\nhttps://security-tracker.debian.org/tracker/CVE-2023-31438\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-31438\nhttps://github.com/systemd/systemd/pull/28886\n","modified":"2026-09-15T03:42:44.088734918Z","published":"2026-01-29T00:50:42.258300Z","withdrawn":"2025-08-03T16:59:06.288Z","upstream":["CVE-2023-31438","GHSA-m3qw-f5f6-m6r3"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2023-31438"}],"affected":[{"package":{"name":"systemd","ecosystem":"Echo","purl":"pkg:deb/echo/systemd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-9070-2f4f-ebc3.json"}}],"schema_version":"1.9.0"}