#1144616 rsyslog: CVE-2026-19654

Package:
src:rsyslog
Source:
src:rsyslog
Submitter:
Salvatore Bonaccorso
Date:
2026-08-19 19:35:04 UTC
Severity:
normal
Tags:
#1144616#5
Date:
2026-08-17 06:58:57 UTC
From:
To:
Hi,

The following vulnerability was published for rsyslog.

CVE-2026-19654[0]:
| A unauthenticated remote peer may lead rsyslogd to crash due to a
| flaw in the optional imptcp module. A crafted input sequence during
| oversize-frame recovery can cause an invalid internal message length
| and terminate rsyslogd. No confidentiality or integrity impact,
| privilege escalation, or code execution has been identified. imtcp
| and the default imptcp framing modes are not affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19654
https://www.cve.org/CVERecord?id=CVE-2026-19654
[1] https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
[2] https://github.com/rsyslog/rsyslog/pull/7410
[3] https://www.openwall.com/lists/oss-security/2026/07/22/5

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1144616#10
Date:
2026-08-19 17:31:12 UTC
From:
To:
Hi Salvatore, hi securit team!

Thanks for the bug report.

Am 17.08.26 um 08:58 schrieb Salvatore Bonaccorso:

According to
https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
it is 8.36.0+, so marking accordingly.

The CVSS metric for this bug says 7.5/10, which I suppose is mostly due
to the network attack vector.

Given the module is not enabled by default and I would suspect it's not
that widely used, I would say a security upload is not necessary and I
would just make a stable upload for rsyslog.

What's your take?

Regards,
Michael

#1144616#17
Date:
2026-08-19 18:53:27 UTC
From:
To:
Sounds good! We've marked it as no-dsa.

The CVSS score is a good example why these are so useless in
practice and why Debian doesn't use them: While this is of course a network
attack vector, it's not like an rsyslog would be exposed to the public internet...

Cheers,
        Moritz

#1144616#22
Date:
2026-08-19 19:33:59 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
rsyslog, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1144616@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Biebl <biebl@debian.org> (supplier of updated rsyslog package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 19 Aug 2026 20:30:39 +0200
Source: rsyslog
Architecture: source
Version: 8.2608.0-1
Distribution: unstable
Urgency: medium
Maintainer: Michael Biebl <biebl@debian.org>
Changed-By: Michael Biebl <biebl@debian.org>
Closes: 1144616
Changes:
 rsyslog (8.2608.0-1) unstable; urgency=medium
 .
   * New upstream version 8.2608.0
     - imptcp: reject invalid regex-framing recovery transitions
       (CVE-2026-19654, Closes: #1144616)
   * Rebase patches.
     Drop patches that have been merged upstream.
   * Enable support for Kubernetes-native log input.
     Ship the new imkubernetes input module within rsyslog-kubernetes.
Checksums-Sha1:
 c68b09ba49c1b57b0f867606e9db96ccaa03a2e4 3796 rsyslog_8.2608.0-1.dsc
 8a6b27d9ea5f18f8c9c0ee9abe0843a61054f281 11825281 rsyslog_8.2608.0.orig.tar.gz
 f1cbd618a08699be2250dc6db74fb4e984a156be 35028 rsyslog_8.2608.0-1.debian.tar.xz
 8a8056ce842a3b600e5dfc188d4acb2479fe31f8 8553 rsyslog_8.2608.0-1_source.buildinfo
Checksums-Sha256:
 8bb89c1217c74ff4d10c2ed87659b92182892e427179d75352df1ff5f3cf17d0 3796 rsyslog_8.2608.0-1.dsc
 e3d60c83405268c422f95feec740455a1cc4b911d00bd8424d5d1272bc509b1a 11825281 rsyslog_8.2608.0.orig.tar.gz
 3fde9041c089cf1920a6239447fc1b8b109327b08a5e4457655da7b15114ec4f 35028 rsyslog_8.2608.0-1.debian.tar.xz
 99abc9180ec778aa03db07820245e6745addad465a53462d6f2798acac1628a4 8553 rsyslog_8.2608.0-1_source.buildinfo
Files:
 d1d158e38a4286afd5e7b939b8a58cf3 3796 admin optional rsyslog_8.2608.0-1.dsc
 4eb2846010ea4587e639a47c396bed3f 11825281 admin optional rsyslog_8.2608.0.orig.tar.gz
 88e12d852033c260888696c134ac6a02 35028 admin optional rsyslog_8.2608.0-1.debian.tar.xz
 68b55615029bc076255c920ed653529d 8553 admin optional rsyslog_8.2608.0-1_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEECbOsLssWnJBDRcxUauHfDWCPItwFAmqF+QcACgkQauHfDWCP
ItyNeQ/9EGAe7wgOWp0LxvxLo8sh5CTam0jrjOktI5cWcCXqdgmcwGvzZF3pSont
KIbt7Zk10V6LpT9RfgyGfa7s93xEaEOSh8MwCcysHhm83qBc+VHWhSsCSXZqE/cS
M/IQ2dGNEaBTJsXWyr8SHU0+oS6m4BRrNTDGnhyUGjF0GrNRgEKdjvssHGY6WW39
ZNe2f6m88g2tdOtRfiewUeQnaeFvZDRrKYrCsL4xhwHUdgg5swixcRN2m8g3JroO
tLcQMG4u0KdReECauSHa+K85aGJyz62fIwKHAZL511/IpKCJXgdHNRGFJqGKnSeG
k5gamWm1hZmIbo+By7aaUV2QjLljjkgb3JtJTky/s/+nCzT936H+846f7IkJ1plh
x0m+5QlHjXW4VUo2Q+3Mi2OFVMSgBw3IYDNWC7m3VW9FUpHBnoQu2GIz+m4r09et
edDgMqUpDn3ETTypZ0+HgC76VLkpsq0AIkv4VFrt7EcgLH/zAAptzEWUOYx6u+vb
YXIoMcdDpLbRTWMXZNbaXCXTK46g+to3pKmcdhX2tHWTBMfddi4S0DyitzHhRzV0
HYFH7X4b2OjBM7drwcJV8+2/dxEhiuQVMJwo4Y9Xj4Y7wQiK+0Uy0zET8u4UKXcr
UIRuQlmaaTyujx9KjHo5v9gp2vnTuvr1aB+A5HkI/TwfPTBVIEQ=
=vTHF
-----END PGP SIGNATURE-----