Описание
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
Отчет
This vulnerability in rsyslog allows an unauthenticated peer to crash the rsyslogd deamon, resulting a a Denial-of-Service, by sending a crafted input sequence. This happens because the malicious input ends creating an invalid internal message length, which crashes the rsyslogd receiving the input. This vulnerability is only exploitable when the following conditions are met:
- imptcp module is explicitly loaded
- There's an imptcp listener using the non-default framing.delimiter.regex mode
- The attacker is able to establish a TCP connection to the target listener
Although this vulnerability has been rated as having an Important severity in upstream, the Red Hat Product Security team has rated it as having a MODERATE severity in supported Red Hat Products. This happens because the conditions described above are not met in default configurations of the
rsyslogpackage as shipped with Red Hat Enterprise Linux Versions.
Меры по смягчению последствий
To mitigate this issue, users that are relying on the imptcp module can implement one of the following options:
- Remove the framing.delimiter.regex from the affected
- Disabled the affected
imptcplistener or unloadimptcpif it's not required - Restrict the network access to the listener to trusted senders only
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | rsyslog | Affected | ||
| Red Hat Enterprise Linux 6 | rsyslog | Affected | ||
| Red Hat Enterprise Linux 6 | rsyslog7 | Affected | ||
| Red Hat Enterprise Linux 7 | rsyslog | Affected | ||
| Red Hat Enterprise Linux 8 | rsyslog | Affected | ||
| Red Hat Enterprise Linux 9 | rsyslog | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw ...
7.5 High
CVSS3