Back

HIGH

Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd

Published Aug 12, 2026

Description

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

Affected products

Remediation

Vendor solution

To mitigate this issue, users that are relying on the imptcp module can implement one of the following options:

1) Remove the framing.delimiter.regex from the affected 2) Disabled the affected `imptcp` listener or unload `imptcp` if it's not required 3) Restrict the network access to the listener to trusted senders only

Red Hat statement

This vulnerability in rsyslog allows an unauthenticated peer to crash the rsyslogd deamon, resulting a a Denial-of-Service, by sending a crafted input sequence. This happens because the malicious input ends creating an invalid internal message length, which crashes the rsyslogd receiving the input. This vulnerability is only exploitable when the following conditions are met: * imptcp module is explicitly loaded * There's an imptcp listener using the non-default framing.delimiter.regex mode * The attacker is able to establish a TCP connection to the target listener Although this vulnerability has been rated as having an Important severity in upstream, the Red Hat Product Security team has rated it as having a MODERATE severity in supported Red Hat Products. This happens because the conditions described above are not met in default configurations of the `rsyslog` package as shipped with Red Hat Enterprise Linux Versions.

Red Hat mitigation

To mitigate this issue, users that are relying on the imptcp module can implement one of the following options: 1) Remove the framing.delimiter.regex from the affected 2) Disabled the affected `imptcp` listener or unload `imptcp` if it's not required 3) Restrict the network access to the listener to trusted senders only

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Aug 12, 2026
Updated Sep 24, 2026
Reserved Aug 12, 2026
CISA Vulnrichment
Updated Aug 13, 2026
NVD
Status Modified
Modified Sep 15, 2026
Red Hat
Severity Important
Public date Jul 22, 2026