The CVE is disputed by upstream. It's part of 3 similar cve's, which are disputed by this article:
https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf
The guy who wrote the article also provides patches, 2 of them are in upstream, 3rd one only on his site.
One of the patches does not completely solve it's cve (CVE-2023-31438). We should consider this not applicable
in the meantime and come back to it later.
https://security-tracker.debian.org/tracker/CVE-2023-31438
https://nvd.nist.gov/vuln/detail/CVE-2023-31438
https://github.com/systemd/systemd/pull/28886