{
  "document": {
    "aggregate_severity": {
      "text": "Medium"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/ubuntu18.04els/vex/2023/cve-2023-31147-els_os-ubuntu18_04els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-08-25T13:39:52Z",
      "generator": {
        "date": "2026-08-25T13:39:52Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2023-31147-ELS_OS-UBUNTU18.04ELS",
      "initial_release_date": "2023-05-25T22:15:00Z",
      "revision_history": [
        {
          "date": "2023-05-25T22:15:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-25T13:39:52Z",
          "number": "2",
          "summary": "Official Publication"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Security update on CVE-2023-31147"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Ubuntu 18.04",
                "product": {
                  "name": "Ubuntu 18.04",
                  "product_id": "Ubuntu-18",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Ubuntu"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
                "product": {
                  "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
                  "product_id": "libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libc-ares-dev@1.14.0-1ubuntu0.2?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libc-ares2-0:1.14.0-1ubuntu0.2.amd64",
                "product": {
                  "name": "libc-ares2-0:1.14.0-1ubuntu0.2.amd64",
                  "product_id": "libc-ares2-0:1.14.0-1ubuntu0.2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/ubuntu/libc-ares2@1.14.0-1ubuntu0.2?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "Canonical Ltd."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                "product": {
                  "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                  "product_id": "libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libc-ares-dev@1.14.0-1ubuntu0.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                "product": {
                  "name": "libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                  "product_id": "libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/cloudlinux/libc-ares2@1.14.0-1ubuntu0.2%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "CloudLinux"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64"
        },
        "product_reference": "libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64"
        },
        "product_reference": "libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64"
        },
        "product_reference": "libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "libc-ares2-0:1.14.0-1ubuntu0.2.amd64 as a component of Ubuntu 18.04",
          "product_id": "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2.amd64"
        },
        "product_reference": "libc-ares2-0:1.14.0-1ubuntu0.2.amd64",
        "relates_to_product_reference": "Ubuntu-18"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-31147",
      "cwe": {
        "id": "CWE-330",
        "name": "Use of Insufficiently Random Values"
      },
      "notes": [
        {
          "category": "description",
          "text": "c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so will generate predictable output. Input from the random number generator is fed into a non-compilant RC4 implementation and may not be as strong as the original RC4 implementation. No attempt is made to look for modern OS-provided CSPRNGs like arc4random() that is widely available. This issue has been fixed in version 1.19.1.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "known_affected": [
          "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
          "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
          "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
          "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2023-31147"
        },
        {
          "category": "external",
          "summary": "https://github.com/c-ares/c-ares/releases/tag/cares-1_19_1",
          "url": "https://github.com/c-ares/c-ares/releases/tag/cares-1_19_1"
        },
        {
          "category": "external",
          "summary": "https://github.com/c-ares/c-ares/security/advisories/GHSA-8r8p-23f3-64c2",
          "url": "https://github.com/c-ares/c-ares/security/advisories/GHSA-8r8p-23f3-64c2"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5Z5XFNXTNPTCBBVXFDNZQVLLIE6VRBY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/B5Z5XFNXTNPTCBBVXFDNZQVLLIE6VRBY/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBFWILTA33LOSV23P44FGTQQIDRJHIY7/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UBFWILTA33LOSV23P44FGTQQIDRJHIY7/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202310-09",
          "url": "https://security.gentoo.org/glsa/202310-09"
        }
      ],
      "release_date": "2023-05-25T22:15:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-08-18T14:37:33.001875Z",
          "details": "This flaw only occurs if the OS CSPRNG is unavailable (e.g., no /dev/urandom on Unix or no RtlGenRandom on Windows), forcing c-ares to fall back to rand(); on contemporary Linux/Windows servers and VMs these CSPRNGs exist by default, so the fallback path is not exercised. Even if reached, it only weakens DNS query‑ID entropy (no secrets exposed) and exploitation still requires the attacker to inject spoofed DNS replies, also predict randomized UDP source ports, and win a timing race—conditions that are operationally difficult. Given these narrow, non‑default preconditions and the limited impact (no availability effect; low confidentiality/integrity), this CVE can be safely deprioritized.",
          "product_ids": [
            "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
            "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 6.5,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-18:libc-ares-dev-0:1.14.0-1ubuntu0.2.amd64",
            "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2+tuxcare.els1.amd64",
            "Ubuntu-18:libc-ares2-0:1.14.0-1ubuntu0.2.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}