CVE-2026-19654

EUVD-2026-57617
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 37.77%
Affected Products (NVD)
VendorProductVersion
rsyslogrsyslog
8.36.0 ≤
𝑥
< 8.2608.0
redhatenterprise_linux
6.0
redhatenterprise_linux
7.0
redhatenterprise_linux
8.0
redhatenterprise_linux
9.0
redhatenterprise_linux
10.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rsyslog
bookworm
postponed
forky
8.2608.0-4
fixed
sid
8.2608.0-4
fixed
trixie
8.2504.0-1+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rsyslog
bionic
needs-triage
focal
needs-triage
jammy
Fixed 8.2112.0-2ubuntu2.4
released
noble
Fixed 8.2312.0-3ubuntu9.3
released
resolute
Fixed 8.2512.0-1ubuntu4.1
released
trusty
needs-triage
xenial
needs-triage
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
rsyslog
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-crypto
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-doc
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-elasticsearch
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-gnutls
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-gssapi
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-kafka
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-logrotate
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-mmaudit
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-mmfields
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-mmjsonparse
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-mmkubernetes
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-mmnormalize
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-mmsnmptrapd
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-mysql
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-omamqp1
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-openssl
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-pgsql
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-relp
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-snmp
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
rsyslog-udpspoof
RHEL 9
0:8.2510.0-2.el9_8.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
rsyslog
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-crypto
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-crypto-debuginfo
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-debuginfo
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-debugsource
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-doc
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-elasticsearch
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-elasticsearch-debuginfo
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-logrotate
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmaudit
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmaudit-debuginfo
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmfields
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmfields-debuginfo
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmjsonparse
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmjsonparse-debuginfo
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmkubernetes
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmkubernetes-debuginfo
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmnormalize
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmnormalize-debuginfo
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmtaghostname
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-mmtaghostname-debuginfo
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-openssl
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
rsyslog-openssl-debuginfo
Amazon Linux 2023
0:8.2204.0-3.amzn2023.0.5
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
rsyslog
Azure Linux 3.0
0:8.2308.0-6.azl3
fixed