Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-19654

Опубликовано: 22 июл. 2026
Источник: redhat
CVSS3: 7.5

Описание

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

Отчет

This vulnerability in rsyslog allows an unauthenticated peer to crash the rsyslogd deamon, resulting a a Denial-of-Service, by sending a crafted input sequence. This happens because the malicious input ends creating an invalid internal message length, which crashes the rsyslogd receiving the input. This vulnerability is only exploitable when the following conditions are met:

  • imptcp module is explicitly loaded
  • There's an imptcp listener using the non-default framing.delimiter.regex mode
  • The attacker is able to establish a TCP connection to the target listener Although this vulnerability has been rated as having an Important severity in upstream, the Red Hat Product Security team has rated it as having a MODERATE severity in supported Red Hat Products. This happens because the conditions described above are not met in default configurations of the rsyslog package as shipped with Red Hat Enterprise Linux Versions.

Меры по смягчению последствий

To mitigate this issue, users that are relying on the imptcp module can implement one of the following options:

  1. Remove the framing.delimiter.regex from the affected
  2. Disabled the affected imptcp listener or unload imptcp if it's not required
  3. Restrict the network access to the listener to trusted senders only

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10rsyslogAffected
Red Hat Enterprise Linux 6rsyslogAffected
Red Hat Enterprise Linux 6rsyslog7Affected
Red Hat Enterprise Linux 7rsyslogAffected
Red Hat Enterprise Linux 8rsyslogAffected
Red Hat Enterprise Linux 9rsyslogAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2502868rsyslog: A configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 дня назад

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

CVSS3: 7.5
nvd
4 дня назад

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

CVSS3: 7.5
debian
4 дня назад

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw ...

7.5 High

CVSS3