No analysis available yet.
Vendor Workaround
To mitigate this issue, users that are relying on the imptcp module can implement one of the following options: 1) Remove the framing.delimiter.regex from the affected 2) Disabled the affected `imptcp` listener or unload `imptcp` if it's not required 3) Restrict the network access to the listener to trusted senders only
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 12 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected. | |
| Title | Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd | |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| Weaknesses | CWE-125 | |
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-08-12T20:46:31.853Z
Reserved: 2026-08-12T18:27:36.578Z
Link: CVE-2026-19654
No data.
Status : Received
Published: 2026-08-12T21:17:38.517
Modified: 2026-08-12T21:17:38.517
Link: CVE-2026-19654
No data.
OpenCVE Enrichment
No data.
-
CWE-125
Out-of-bounds Read