An issue was discovered in systemd 253. An attacker can modify a sealed log file such that, in some views, not all existing and sealed log messages are displayed. NOTE: the vendor reportedly sent "a reply denying that any of the finding was a security vulnerability."
The product does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.
Link | Tags |
---|---|
https://github.com/systemd/systemd/releases | release notes |
https://github.com/kastel-security/Journald/blob/main/journald-publication.pdf | technical description |
https://github.com/kastel-security/Journald | third party advisory |