Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-78002

Опубликовано: 27 авг. 2026
Источник: debian
EPSS Низкий

Описание

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rsyslogfixed8.2608.0-4package
rsyslogfixed8.2504.0-1+deb13u2trixiepackage
rsyslogpostponedbookwormpackage

Примечания

  • https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3

  • https://github.com/rsyslog/rsyslog/pull/7525

  • https://github.com/rsyslog/rsyslog/commit/667e3f61aec5ee02c5c2ee6f0f8accf6fe4301a9

  • https://www.openwall.com/lists/oss-security/2026/08/29/1

EPSS

Процентиль: 48%
0.00612
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
21 день назад

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.

CVSS3: 7.5
redhat
23 дня назад

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.

CVSS3: 7.5
nvd
21 день назад

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.

msrc
11 дней назад

Rsyslog: rsyslog: denial of service via heap buffer overflow in rainerscript replace() function

EPSS

Процентиль: 48%
0.00612
Низкий