Description
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
Published: 2026-08-12
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A crafted input sequence sent over the network to the optional imptcp input module of rsyslog can cause the rsyslog daemon to crash by creating an invalid internal message length during oversize‑frame recovery. The failure results in a denial of service and does not lead to any compromise of confidentiality, integrity, privilege escalation, or code execution.

Affected Systems

Red Hat Enterprise Linux 6, 7, 8, 9, and 10 when the rsyslog service is configured to use the imptcp module.

Risk and Exploitability

The vulnerability has a CVSS score of 7.5, indicating medium‑high severity, and has no reported exploitation probability (EPSS data unavailable). It is not listed in the CISA KEV catalog. Exploitation requires that the affected system exposes an imptcp listener and that an unauthenticated remote peer can reach it, making the attack vector a remote network connection to the listening port.

Generated by OpenCVE AI on August 13, 2026 at 02:19 UTC.

Remediation

Vendor Workaround

To mitigate this issue, users that are relying on the imptcp module can implement one of the following options: 1) Remove the framing.delimiter.regex from the affected 2) Disabled the affected `imptcp` listener or unload `imptcp` if it's not required 3) Restrict the network access to the listener to trusted senders only


OpenCVE Recommended Actions

  • Apply any vendor‑supplied patch or update for rsyslog that addresses this issue
  • Remove the framing.delimiter.regex setting from the rsyslog configuration file
  • Disable or unload the imptcp module if it is not required for your logging workflow
  • Limit incoming connections to the imptcp listener to trusted hosts only

Generated by OpenCVE AI on August 13, 2026 at 02:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Rsyslog
Rsyslog rsyslog
CPEs cpe:2.3:a:rsyslog:rsyslog:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
Vendors & Products Rsyslog
Rsyslog rsyslog

Sat, 15 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 12 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Description A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
Title Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-125
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux
Rsyslog Rsyslog
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-27T14:50:47.138Z

Reserved: 2026-08-12T18:27:36.578Z

Link: CVE-2026-19654

cve-icon Vulnrichment

Updated: 2026-08-13T12:58:42.657Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-12T21:17:38.517

Modified: 2026-08-27T17:17:41.503

Link: CVE-2026-19654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:39:11Z

Weaknesses