Impact
Rsyslog’s optional mmpstrucdata plugin contains a stack‐based buffer overflow in the parseSD_PARAM routine, which allocates a 32 KB stack buffer for RFC5424 structured‑data parameters but calls parsePARAM_VALUE without passing a destination size. A crafted parameter larger than the buffer can overwrite adjacent stack memory, causing the rsyslog process to crash. The vulnerability is a classic buffer overflow (CWE‑120) with a potential stack‐based error condition (CWE‑121). Only a denial‑of‑service scenario has been demonstrated; code execution has not been proven by the CVE description.
Affected Systems
The flaw exists in rsyslog releases from 7.5.4 through the 8.2605.x series; the fix was introduced in version 8.2606.0. Because the plugin is optional, systems that never enable mmpstrucdata or that enforce a MaxMessageSize below the overflow threshold are not affected. Deployments that enable the plugin and accept RFC5424 messages larger than the internal buffer size remain vulnerable until the code is patched or the plugin usage is disabled.
Risk and Exploitability
The CVSS score of 8.1 classifies this as high severity, while the EPSS score of < 1% indicates a low probability of exploitation as of the latest data. The vulnerability is not listed in the CISA KEV catalog, and there is no public evidence of an active exploit. A remote unauthenticated attacker can send a specially crafted RFC5424 message to a rsyslog instance to trigger the overflow, leading to a crash and interruption of log collection. No documented code‑execution capability has been demonstrated, so the principal risk remains service disruption.
OpenCVE Enrichment
Ubuntu USN