Rsyslogd Crash Vulnerability in Rsyslog Optional imptcp Module
CVE-2026-19654

7.5HIGH

What is CVE-2026-19654?

An issue has been identified in Rsyslog's optional imptcp module that may cause the rsyslogd service to crash when handling a specific sequence of crafted inputs during oversize-frame recovery. This flaw results in an invalid internal message length, leading to service termination. While no impacts to confidentiality, integrity, privilege escalation, or code execution have been discovered, users should be aware of this DoS vulnerability to ensure the stability and availability of their logging services.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.