7.5

CVE-2026-19654

Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rsyslog ≫ Rsyslog Version >= 8.36.0 < 8.2608.0
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Version 9.0
Redhat ≫ Enterprise Linux Version 10.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.4% 0.333
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://access.redhat.com/security/cve/CVE-2026-19654
Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2502868
Third Party Advisory
Issue Tracking
https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:66405
https://access.redhat.com/errata/RHSA-2026:67583
https://access.redhat.com/errata/RHSA-2026:67584
https://access.redhat.com/errata/RHSA-2026:71603