{
  "document": {
    "aggregate_severity": {
      "text": "Low"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu18.04els/vex/2023/cve-2023-31124-els_os-ubuntu18_04els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-25T13:39:52Z",
      "generator": {
        "date": "2026-08-25T13:39:52Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2023-31124-ELS_OS-UBUNTU18.04ELS",
      "initial_release_date": "2023-05-25T22:15:00Z",
      "revision_history": [
        {
          "date": "2023-05-25T22:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-25T13:39:52Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2023-31124"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 18.04",
                "product": {
                  "name": "Ubuntu 18.04",
                  "product_id": "Ubuntu-18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
                "product": {
                  "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
                  "product_id": "libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libc-ares-dev@1.14.0-1ubuntu0.2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libc-ares2-0:1.14.0-1ubuntu0.2.amd64",
                "product": {
                  "name": "libc-ares2-0:1.14.0-1ubuntu0.2.amd64",
                  "product_id": "libc-ares2-0:1.14.0-1ubuntu0.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libc-ares2@1.14.0-1ubuntu0.2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                "product": {
                  "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                  "product_id": "libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libc-ares-dev@1.14.0-1ubuntu0.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                "product": {
                  "name": "libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                  "product_id": "libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libc-ares2@1.14.0-1ubuntu0.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64"
        },
        "product_reference": "libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64"
        },
        "product_reference": "libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64"
        },
        "product_reference": "libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libc-ares2-0:1.14.0-1ubuntu0.2.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2.amd64"
        },
        "product_reference": "libc-ares2-0:1.14.0-1ubuntu0.2.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-31124",
      "cwe": {
        "id": "CWE-330",
        "name": "Use of Insufficiently Random Values"
      },
      "notes": [
        {
          "category": "description",
          "text": "c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android.  This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patched in version 1.19.1.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
          "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
          "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
          "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2023-31124"
        },
        {
          "category": "external",
          "summary": "https://github.com/c-ares/c-ares/releases/tag/cares-1_19_1",
          "url": "https://github.com/c-ares/c-ares/releases/tag/cares-1_19_1"
        },
        {
          "category": "external",
          "summary": "https://github.com/c-ares/c-ares/security/advisories/GHSA-54xr-f67r-4pc4",
          "url": "https://github.com/c-ares/c-ares/security/advisories/GHSA-54xr-f67r-4pc4"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5Z5XFNXTNPTCBBVXFDNZQVLLIE6VRBY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5Z5XFNXTNPTCBBVXFDNZQVLLIE6VRBY/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBFWILTA33LOSV23P44FGTQQIDRJHIY7/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBFWILTA33LOSV23P44FGTQQIDRJHIY7/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202310-09",
          "url": "https://security.gentoo.org/glsa/202310-09"
        }
      ],
      "release_date": "2023-05-25T22:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-18T14:37:38.623237Z",
          "details": "This flaw only manifests in c-ares binaries produced by cross-compiling with Autotools when CARES_RANDOM_FILE is left unset (e.g., Android/aarch64 scenarios); native Linux server builds define a secure OS RNG and are not affected. Even in affected custom cross-builds, it merely weakens randomness for DNS query IDs—no confidentiality or availability impact—with exploitation requiring high‑complexity network spoofing. Given the narrow, non‑default build condition and integrity‑only, low impact, this CVE can be safely deprioritized.",
          "product_ids": [
            "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
            "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.7,
            "baseSeverity": "LOW",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
            "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    }
  ]
}