Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd
Published Aug 12, 2026
7.5
HIGHCVSS 3.1
EPSS 0.47%
Description
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 8 | affected |
|
- ≥ 8.36.0 · < 8.2608.0
- 6.0
- 7.0
- 8.0
- 9.0
- 10.0
No data.
Red Hat Enterprise Linux 10
rsyslog-0:8.2510.0-5.el10_2.1
Fixed · RHSA-2026:67584
Red Hat Enterprise Linux 10.0 Extended Update Support
rsyslog-0:8.2412.0-1.el10_0.1
Fixed · RHSA-2026:66405
Red Hat Enterprise Linux 9
rsyslog-0:8.2510.0-2.el9_8.1
Fixed · RHSA-2026:67583
Red Hat Enterprise Linux 6
rsyslog
Not affected
Red Hat Enterprise Linux 6
rsyslog7
Not affected
Red Hat Enterprise Linux 7
rsyslog
Not affected
Red Hat Enterprise Linux 8
rsyslog
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | rsyslog-0:8.2510.0-5.el10_2.1 | Fixed | RHSA-2026:67584 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | rsyslog-0:8.2412.0-1.el10_0.1 | Fixed | RHSA-2026:66405 |
| Red Hat Enterprise Linux 9 | rsyslog-0:8.2510.0-2.el9_8.1 | Fixed | RHSA-2026:67583 |
| Red Hat Enterprise Linux 6 | rsyslog | Not affected | n/a |
| Red Hat Enterprise Linux 6 | rsyslog7 | Not affected | n/a |
| Red Hat Enterprise Linux 7 | rsyslog | Not affected | n/a |
| Red Hat Enterprise Linux 8 | rsyslog | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
To mitigate this issue, users that are relying on the imptcp module can implement one of the following options:
1) Remove the framing.delimiter.regex from the affected 2) Disabled the affected `imptcp` listener or unload `imptcp` if it's not required 3) Restrict the network access to the listener to trusted senders only
Red Hat statement
This vulnerability in rsyslog allows an unauthenticated peer to crash the rsyslogd deamon, resulting a a Denial-of-Service, by sending a crafted input sequence. This happens because the malicious input ends creating an invalid internal message length, which crashes the rsyslogd receiving the input. This vulnerability is only exploitable when the following conditions are met: * imptcp module is explicitly loaded * There's an imptcp listener using the non-default framing.delimiter.regex mode * The attacker is able to establish a TCP connection to the target listener Although this vulnerability has been rated as having an Important severity in upstream, the Red Hat Product Security team has rated it as having a MODERATE severity in supported Red Hat Products. This happens because the conditions described above are not met in default configurations of the `rsyslog` package as shipped with Red Hat Enterprise Linux Versions.
Red Hat mitigation
To mitigate this issue, users that are relying on the imptcp module can implement one of the following options: 1) Remove the framing.delimiter.regex from the affected 2) Disabled the affected `imptcp` listener or unload `imptcp` if it's not required 3) Restrict the network access to the listener to trusted senders only
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Aug 13, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Aug–Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.47% (0.00466) | 37.97th | v5 (v2026.06.15) |
| Aug 13, 2026 | 0.40% (0.00402) | 33.27th | v5 (v2026.06.15) |
References (9)
- https://access.redhat.com/errata/RHSA-2026:66405 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:67583 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:67584 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:71603 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-19654 vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2502868 issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory
- https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-19654
- https://www.cve.org/CVERecord?id=CVE-2026-19654
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:66405 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:67583 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:67584 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2026:71603 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2026-19654 | vdb-entryx_refsource_REDHATThird Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2502868 | issue-trackingx_refsource_REDHATIssue TrackingThird Party Advisory | |
| https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29 | Vendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-19654 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-19654 |
Change history (0)
No recorded changes yet.