CVE-2026-19654
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
Zayıflık
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
Etkilenen ürünler
- rsyslog rsyslog
- redhat enterprise_linux
Kaynaklar
- https://access.redhat.com/errata/RHSA-2026:66405
- https://access.redhat.com/errata/RHSA-2026:67583
- https://access.redhat.com/errata/RHSA-2026:67584
- https://access.redhat.com/security/cve/CVE-2026-19654
- https://bugzilla.redhat.com/show_bug.cgi?id=2502868
- https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
Açığı bir saldırgandan önce siz bulun.
GitHub ile giriş yapın ve ilk denetiminizi bir dakikadan kısa sürede başlatın. Ücretsiz plan için kredi kartı gerekmez.