A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.
{ "ubuntu_priority": "low", "priority_reason": "DNSSEC is an experimental feature in systemd with known issues" }