ECHO-9070-2f4f-ebc3

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-9070-2f4f-ebc3.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-9070-2f4f-ebc3
Upstream
  • GHSA-m3qw-f5f6-m6r3
Withdrawn
2025-08-03T16:59:06Z
Published
2026-01-29T00:50:42Z
Modified
2026-09-15T03:42:44Z
Summary
The CVE is disputed by upstream. It's part of 3 similar cve's, which are disputed by this article: https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf The guy who wrote the article also provides patches, 2 of them are in upstream, 3rd one only on his site. One of the patches does not completely solve it's cve (CVE-2023-31438). We should consider this not applicable in the meantime and come back to it later. https://security-tracker.debian.org/tracker/CVE-2023-31438 https://nvd.nist.gov/vuln/detail/CVE-2023-31438 https://github.com/systemd/systemd/pull/28886
Details
References

Affected packages

Echo / systemd

Package

Name
systemd
Purl
pkg:deb/echo/systemd

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://advisory.echohq.com/osv/ECHO-9070-2f4f-ebc3.json"