- Package:
- src:rsyslog
- Source:
- src:rsyslog
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-08-31 17:18:05 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerability was published for rsyslog. CVE-2026-19654[0]: | A unauthenticated remote peer may lead rsyslogd to crash due to a | flaw in the optional imptcp module. A crafted input sequence during | oversize-frame recovery can cause an invalid internal message length | and terminate rsyslogd. No confidentiality or integrity impact, | privilege escalation, or code execution has been identified. imtcp | and the default imptcp framing modes are not affected. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-19654 https://www.cve.org/CVERecord?id=CVE-2026-19654 [1] https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29 [2] https://github.com/rsyslog/rsyslog/pull/7410 [3] https://www.openwall.com/lists/oss-security/2026/07/22/5 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
Hi Salvatore, hi securit team! Thanks for the bug report. Am 17.08.26 um 08:58 schrieb Salvatore Bonaccorso: According to https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29 it is 8.36.0+, so marking accordingly. The CVSS metric for this bug says 7.5/10, which I suppose is mostly due to the network attack vector. Given the module is not enabled by default and I would suspect it's not that widely used, I would say a security upload is not necessary and I would just make a stable upload for rsyslog. What's your take? Regards, Michael
Sounds good! We've marked it as no-dsa.
The CVSS score is a good example why these are so useless in
practice and why Debian doesn't use them: While this is of course a network
attack vector, it's not like an rsyslog would be exposed to the public internet...
Cheers,
Moritz
We believe that the bug you reported is fixed in the latest version of
rsyslog, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144616@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Michael Biebl <biebl@debian.org> (supplier of updated rsyslog package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 19 Aug 2026 20:30:39 +0200
Source: rsyslog
Architecture: source
Version: 8.2608.0-1
Distribution: unstable
Urgency: medium
Maintainer: Michael Biebl <biebl@debian.org>
Changed-By: Michael Biebl <biebl@debian.org>
Closes: 1144616
Changes:
rsyslog (8.2608.0-1) unstable; urgency=medium
.
* New upstream version 8.2608.0
- imptcp: reject invalid regex-framing recovery transitions
(CVE-2026-19654, Closes: #1144616)
* Rebase patches.
Drop patches that have been merged upstream.
* Enable support for Kubernetes-native log input.
Ship the new imkubernetes input module within rsyslog-kubernetes.
Checksums-Sha1:
c68b09ba49c1b57b0f867606e9db96ccaa03a2e4 3796 rsyslog_8.2608.0-1.dsc
8a6b27d9ea5f18f8c9c0ee9abe0843a61054f281 11825281 rsyslog_8.2608.0.orig.tar.gz
f1cbd618a08699be2250dc6db74fb4e984a156be 35028 rsyslog_8.2608.0-1.debian.tar.xz
8a8056ce842a3b600e5dfc188d4acb2479fe31f8 8553 rsyslog_8.2608.0-1_source.buildinfo
Checksums-Sha256:
8bb89c1217c74ff4d10c2ed87659b92182892e427179d75352df1ff5f3cf17d0 3796 rsyslog_8.2608.0-1.dsc
e3d60c83405268c422f95feec740455a1cc4b911d00bd8424d5d1272bc509b1a 11825281 rsyslog_8.2608.0.orig.tar.gz
3fde9041c089cf1920a6239447fc1b8b109327b08a5e4457655da7b15114ec4f 35028 rsyslog_8.2608.0-1.debian.tar.xz
99abc9180ec778aa03db07820245e6745addad465a53462d6f2798acac1628a4 8553 rsyslog_8.2608.0-1_source.buildinfo
Files:
d1d158e38a4286afd5e7b939b8a58cf3 3796 admin optional rsyslog_8.2608.0-1.dsc
4eb2846010ea4587e639a47c396bed3f 11825281 admin optional rsyslog_8.2608.0.orig.tar.gz
88e12d852033c260888696c134ac6a02 35028 admin optional rsyslog_8.2608.0-1.debian.tar.xz
68b55615029bc076255c920ed653529d 8553 admin optional rsyslog_8.2608.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEECbOsLssWnJBDRcxUauHfDWCPItwFAmqF+QcACgkQauHfDWCP
ItyNeQ/9EGAe7wgOWp0LxvxLo8sh5CTam0jrjOktI5cWcCXqdgmcwGvzZF3pSont
KIbt7Zk10V6LpT9RfgyGfa7s93xEaEOSh8MwCcysHhm83qBc+VHWhSsCSXZqE/cS
M/IQ2dGNEaBTJsXWyr8SHU0+oS6m4BRrNTDGnhyUGjF0GrNRgEKdjvssHGY6WW39
ZNe2f6m88g2tdOtRfiewUeQnaeFvZDRrKYrCsL4xhwHUdgg5swixcRN2m8g3JroO
tLcQMG4u0KdReECauSHa+K85aGJyz62fIwKHAZL511/IpKCJXgdHNRGFJqGKnSeG
k5gamWm1hZmIbo+By7aaUV2QjLljjkgb3JtJTky/s/+nCzT936H+846f7IkJ1plh
x0m+5QlHjXW4VUo2Q+3Mi2OFVMSgBw3IYDNWC7m3VW9FUpHBnoQu2GIz+m4r09et
edDgMqUpDn3ETTypZ0+HgC76VLkpsq0AIkv4VFrt7EcgLH/zAAptzEWUOYx6u+vb
YXIoMcdDpLbRTWMXZNbaXCXTK46g+to3pKmcdhX2tHWTBMfddi4S0DyitzHhRzV0
HYFH7X4b2OjBM7drwcJV8+2/dxEhiuQVMJwo4Y9Xj4Y7wQiK+0Uy0zET8u4UKXcr
UIRuQlmaaTyujx9KjHo5v9gp2vnTuvr1aB+A5HkI/TwfPTBVIEQ=
=vTHF
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
rsyslog, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1144616@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Michael Biebl <biebl@debian.org> (supplier of updated rsyslog package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 24 Aug 2026 15:56:02 +0200
Source: rsyslog
Architecture: source
Version: 8.2504.0-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Michael Biebl <biebl@debian.org>
Changed-By: Michael Biebl <biebl@debian.org>
Closes: 1141981 1144616
Changes:
rsyslog (8.2504.0-1+deb13u1) trixie; urgency=medium
.
* omfwd regression fix: avoid false active target change log message.
Patch backported from upstream Git. (Closes: #1141981)
* imptcp: reject invalid regex-framing recovery transitions.
(CVE-2026-19654, Closes: #1144616)
Checksums-Sha1:
8deaf36214015a4ebff6293e8d0007698afb25f7 3452 rsyslog_8.2504.0-1+deb13u1.dsc
7e4ddc551dbd97662d7a6184be3a36ed4aaa0f40 34268 rsyslog_8.2504.0-1+deb13u1.debian.tar.xz
9660a843ee4ab8e960c3a0dd95a1bed67313e46d 7905 rsyslog_8.2504.0-1+deb13u1_source.buildinfo
Checksums-Sha256:
5467bfa9e4ac35ddd746ea2e5ee9ad466473026f3e6c1129d35e88ccca277a78 3452 rsyslog_8.2504.0-1+deb13u1.dsc
f16d88d41ca75707aa2d99704d019bbaece865239d720b3c99bfe93dd0e79661 34268 rsyslog_8.2504.0-1+deb13u1.debian.tar.xz
10566e6fc4d61bc62db673e715f5eeb98387871eba8c61f71f557e13dc086bfb 7905 rsyslog_8.2504.0-1+deb13u1_source.buildinfo
Files:
92d46699b776bdeebecc9a863d6ccbd5 3452 admin optional rsyslog_8.2504.0-1+deb13u1.dsc
078389082ee4311e256896acd190962a 34268 admin optional rsyslog_8.2504.0-1+deb13u1.debian.tar.xz
7139850a4ea78f08e3cbac47ba708d77 7905 admin optional rsyslog_8.2504.0-1+deb13u1_source.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEECbOsLssWnJBDRcxUauHfDWCPItwFAmqMTh8ACgkQauHfDWCP
Itw5yBAAgS7baRrBaqoHW38NqGr3urrJn0BN9Nj0vbgPU9xWRdt1OWnDpGsKMhY6
6IrfDlvlCijxZL+jBoMw9DZzU3FE/E7oAxeLa3OdHYGt66LTUab318oAS3gGDebn
45YBW/ZkFQzbrVN9soRCdECyuCxJdJ4gdGtmbsnXX+loqFK+AHapROPtZb/lZger
F46htMYuLQmKnrVACgna0hm/lcVQJbNyAQ4f31+dtQe7wZn5UmBU9JH+dizGn6Hq
SoUn1mWaRX179C4UnnAEzwBylQ+m+z5VLYcRvSHR2286EsQrkLDei1sG5HvntwSk
FG1hLY2PJR6ZF1Kj8efcPDlCcYVOpOU4RabpOHiVFJb6jCyDM5b6FJrayY5sJhTA
A/NBA71Bd0kLeFmsSDaP4a7YeuCJN2CXOCYBqMYoMx4hJimlqX67ezX0HA2qyDE6
7NHnfwDEmG1YajHY+KFoatMN+bFUgySDH1Z0lbi624I7g4jiVVA8TnFDhJUgz9Zj
NUtSphDmT1I0EPuCZB3BS75QLiR6Z1Y3EQAZ9TbZ6a2WkbvYnVHTDEyO5XTTdmH9
1PcYmtqv++BFVzFW1JZ2vCCeYV7xySOFlt51IvhI8vKWTADYzg2+zjBWAcGBU6nn
7Nt+JW+yUFpL3+wNbLsBYE8ui9LYoj8KGNjZk/A0THjgVoDEGgY=
=RcY4
-----END PGP SIGNATURE-----