Description
Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer and calls parsePARAM_VALUE without supplying the destination size. A remote unauthenticated attacker whose crafted RFC5424 message reaches an action using mmpstrucdata can provide a structured-data parameter larger than that buffer when MaxMessageSize permits it, causing an attacker-controlled stack overwrite. Deployments that do not install and use the plugin, or whose effective message-size limit remains below the required threshold, are not affected by this issue. The demonstrated impact is a crash and interruption of log collection; code execution is not demonstrated. This issue is fixed in version 8.2606.0.
Published: 2026-09-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote stack buffer overflow that may crash rsyslog process
Action: Patch immediately
AI Analysis

Impact

Rsyslog’s optional mmpstrucdata plugin contains a stack‐based buffer overflow in the parseSD_PARAM routine, which allocates a 32 KB stack buffer for RFC5424 structured‑data parameters but calls parsePARAM_VALUE without passing a destination size. A crafted parameter larger than the buffer can overwrite adjacent stack memory, causing the rsyslog process to crash. The vulnerability is a classic buffer overflow (CWE‑120) with a potential stack‐based error condition (CWE‑121). Only a denial‑of‑service scenario has been demonstrated; code execution has not been proven by the CVE description.

Affected Systems

The flaw exists in rsyslog releases from 7.5.4 through the 8.2605.x series; the fix was introduced in version 8.2606.0. Because the plugin is optional, systems that never enable mmpstrucdata or that enforce a MaxMessageSize below the overflow threshold are not affected. Deployments that enable the plugin and accept RFC5424 messages larger than the internal buffer size remain vulnerable until the code is patched or the plugin usage is disabled.

Risk and Exploitability

The CVSS score of 8.1 classifies this as high severity, while the EPSS score of < 1% indicates a low probability of exploitation as of the latest data. The vulnerability is not listed in the CISA KEV catalog, and there is no public evidence of an active exploit. A remote unauthenticated attacker can send a specially crafted RFC5424 message to a rsyslog instance to trigger the overflow, leading to a crash and interruption of log collection. No documented code‑execution capability has been demonstrated, so the principal risk remains service disruption.

Generated by OpenCVE AI on September 23, 2026 at 16:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade rsyslog to version 8.2606.0 or later to apply the fixed bounds‑checking logic for mmpstrucdata parsing.
  • If an upgrade cannot be performed immediately, disable or remove the mmpstrucdata plugin from the rsyslog configuration to eliminate the vulnerable code path entirely.
  • As a temporary mitigation, lower the MaxMessageSize setting to a value below the size that triggers the overflow so that oversized structured‑data parameters are rejected before parsing.

Generated by OpenCVE AI on September 23, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8598-1 rsyslog vulnerabilities
History

Wed, 23 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics threat_severity

None

threat_severity

Important


Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
First Time appeared Rsyslog
Rsyslog rsyslog
Vendors & Products Rsyslog
Rsyslog rsyslog

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer and calls parsePARAM_VALUE without supplying the destination size. A remote unauthenticated attacker whose crafted RFC5424 message reaches an action using mmpstrucdata can provide a structured-data parameter larger than that buffer when MaxMessageSize permits it, causing an attacker-controlled stack overwrite. Deployments that do not install and use the plugin, or whose effective message-size limit remains below the required threshold, are not affected by this issue. The demonstrated impact is a crash and interruption of log collection; code execution is not demonstrated. This issue is fixed in version 8.2606.0.
Title Rsyslog: mmpstrucdata stack buffer overflow with oversized RFC5424 structured data
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-21T20:49:39.195Z

Reserved: 2026-07-10T16:27:03.094Z

Link: CVE-2026-61548

cve-icon Vulnrichment

Updated: 2026-09-18T17:11:33.491Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T17:16:58.190

Modified: 2026-09-24T21:22:19.873

Link: CVE-2026-61548

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-18T16:54:28Z

Links: CVE-2026-61548 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T16:30:08Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-121

    Stack-based Buffer Overflow