Impact
A flaw in rsyslog allows an unauthenticated remote attacker to trigger a heap buffer overflow in the RainerScript replace() function by sending specially crafted syslog messages. The buffer size calculation is incorrect during string replacement, causing memory corruption that results in a denial of service on the affected system. No escalation of privileges or code execution is stated, and the impact is limited to service disruption.
Affected Systems
Red Hat Enterprise Linux 6, 7, 8, 9 and 10 are all affected by this vulnerability. No specific subversions are listed, indicating that any installation running rsyslog on these operating systems is vulnerable.
Risk and Exploitability
The CVSS score is 7.5, indicating high severity. EPSS data is unavailable and the vulnerability is not listed in CISA KEV, suggesting limited publicly known exploitation. The likely attack vector is remote delivery of crafted syslog traffic over UDP or TCP to the standard rsyslog service port 514, leading to a DoS but not to remote code execution.
OpenCVE Enrichment