{"id":"ECHO-9a90-0cdd-d9c7","summary":"The CVE is disputed by upstream. Its part of 3 similar cve's, which are disputed by this article:\nhttps://github.com/kastel-security/Journald/blob/main/journald-publication.pdf\nThe guy who wrote the article also provides patches, 2 of them are in upstream, 3rd one only on his site.\nOne of the patches does not completely solve its cve (CVE-2023-31438). We should consider this not applicable\nin the meantime and come back to it later.\nhttps://security-tracker.debian.org/tracker/CVE-2023-31437\nhttps://nvd.nist.gov/vuln/detail/CVE-2023-31437\n","modified":"2026-09-15T03:42:39.371874859Z","published":"2026-01-29T00:50:42.219197Z","withdrawn":"2025-08-03T16:59:06.288Z","upstream":["CVE-2023-31437","GHSA-9mv8-4v9g-hm48"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2023-31437"}],"affected":[{"package":{"name":"systemd","ecosystem":"Echo","purl":"pkg:deb/echo/systemd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-9a90-0cdd-d9c7.json"}}],"schema_version":"1.9.0"}