Stack Buffer Overflow in Rsyslog Due to mmpstrucdata Plugin Vulnerability
CVE-2026-61548

8.1HIGH

Key Information:

Vendor

Rsyslog

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-61548?

The mmpstrucdata plugin in Rsyslog versions 7.5.4 to 8.2606.0 contains a flaw in the parseSD_PARAM function, leading to a potential stack buffer overflow. An attacker could exploit this vulnerability by sending a crafted RFC5424 message with a structured-data parameter that exceeds the allocated buffer size. If the MaxMessageSize setting permits, this could result in a remote unauthenticated attacker causing a stack overwrite, leading to log collection disruptions. The issue has been resolved in version 8.2606.0, emphasizing the importance of keeping software updated.

Affected Version(s)

rsyslog >= 7.5.4, < 8.2606.0

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.