CVE-2026-19654

high

Description

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

References

https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29

https://bugzilla.redhat.com/show_bug.cgi?id=2502868

https://access.redhat.com/security/cve/CVE-2026-19654

Details

Source: Mitre, NVD

Published: 2026-08-12

Updated: 2026-08-13

Risk Information

CVSS v2

Base Score: 7.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

Severity: High

CVSS v3

Base Score: 7.5

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity: High