Heap Buffer Overflow Vulnerability in Rsyslog Affects Unauthenticated Systems
CVE-2026-78002
7.5HIGH
What is CVE-2026-78002?
A flaw in Rsyslog allows an unauthenticated remote attacker to exploit a heap buffer overflow in the RainerScript replace() function. By sending specially crafted syslog messages, an attacker can trigger this vulnerability, resulting from incorrect buffer size calculations during string replacements. This can lead to memory corruption, potentially causing a denial of service effect on the targeted system.