Impact
A crafted input sequence sent over the network to the optional imptcp input module of rsyslog can cause the rsyslog daemon to crash by creating an invalid internal message length during oversize‑frame recovery. The failure results in a denial of service and does not lead to any compromise of confidentiality, integrity, privilege escalation, or code execution.
Affected Systems
Red Hat Enterprise Linux 6, 7, 8, 9, and 10 when the rsyslog service is configured to use the imptcp module.
Risk and Exploitability
The vulnerability has a CVSS score of 7.5, indicating medium‑high severity, and has no reported exploitation probability (EPSS data unavailable). It is not listed in the CISA KEV catalog. Exploitation requires that the affected system exposes an imptcp listener and that an unauthenticated remote peer can reach it, making the attack vector a remote network connection to the listening port.
OpenCVE Enrichment