CVE-2026-19654

NameCVE-2026-19654
DescriptionA unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144616

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rsyslog (PTS)bullseye (security), bullseye8.2102.0-2+deb11u1vulnerable
bookworm8.2302.0-1+deb12u1vulnerable
trixie8.2504.0-1vulnerable
forky8.2606.0-4vulnerable
sid8.2608.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
rsyslogsource(unstable)8.2608.0-11144616

Notes

[trixie] - rsyslog <no-dsa> (Minor issue)
https://www.openwall.com/lists/oss-security/2026/07/22/5
https://github.com/rsyslog/rsyslog/pull/7410
https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29

Search for package or bug name: Reporting problems