#1145980 rsyslog: CVE-2026-78002

Package:
src:rsyslog
Source:
src:rsyslog
Submitter:
Salvatore Bonaccorso
Date:
2026-08-31 17:18:05 UTC
Severity:
normal
Tags:
#1145980#5
Date:
2026-08-28 14:06:13 UTC
From:
To:
Hi,

The following vulnerability was published for rsyslog.

CVE-2026-78002[0]:
| A flaw was found in rsyslog. An unauthenticated remote attacker can
| trigger a heap buffer overflow in the RainerScript `replace()`
| function by sending specially crafted syslog messages. This
| vulnerability arises from an incorrect buffer size calculation
| during string replacement, causing memory corruption. Successful
| exploitation can lead to a denial of service (DoS) for the affected
| system.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-78002
https://www.cve.org/CVERecord?id=CVE-2026-78002
[1] https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1145980#10
Date:
2026-08-28 21:00:33 UTC
From:
To:
Hi Salvatore

Am 28.08.26 um 16:06 schrieb Salvatore Bonaccorso:

I've adjusted according to the upstream version information at [1]

Do you want me to fix that via stable or stable-security?



Regards,
Michael

#1145980#19
Date:
2026-08-28 21:10:19 UTC
From:
To:
Seems I missed the "="  in "<= 8.2608.0". Removing the fixed tag
accordingly.
Not surprisingly, there is no upstream fix (yet).

Michael

#1145980#26
Date:
2026-08-29 04:43:23 UTC
From:
To:
Hi Michael,

The fix upstream is at
https://github.com/rsyslog/rsyslog/commit/667e3f61aec5ee02c5c2ee6f0f8accf6fe4301a9
.

Regarding the question on th route for trixie, I do not think this
warrants a DSA. With the point release on 12th sepember it would be
tough great if you can batch in all open known issues for rsyslog
there?

Regards,
Salvatore

#1145980#31
Date:
2026-08-30 00:06:17 UTC
From:
To:
Hello,

Bug #1145980 in rsyslog reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/debian/rsyslog/-/commit/2872da51cd96a21cecd3143a57e80718a5cbb00f
------------------------------------------------------------------------
rainerscript: Avoid heap buffer overflow in replace() function

Patch cherry-picked from upstream Git.

CVE-2026-78002

Closes: #1145980
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1145980

#1145980#38
Date:
2026-08-30 00:18:54 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
rsyslog, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145980@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Biebl <biebl@debian.org> (supplier of updated rsyslog package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 30 Aug 2026 01:58:01 +0200
Source: rsyslog
Architecture: source
Version: 8.2608.0-4
Distribution: unstable
Urgency: medium
Maintainer: Michael Biebl <biebl@debian.org>
Changed-By: Michael Biebl <biebl@debian.org>
Closes: 1145980
Changes:
 rsyslog (8.2608.0-4) unstable; urgency=medium
 .
   * rainerscript: Avoid heap buffer overflow in replace() function.
     Patch cherry-picked from upstream Git.
     (CVE-2026-78002, Closes: #1145980)
Checksums-Sha1:
 3aafb44a09f4beea2e5a9ef8ec0232c1e53aad4c 3796 rsyslog_8.2608.0-4.dsc
 92b850a2da4d6165870b02e77b3d4eca3056fd2a 35948 rsyslog_8.2608.0-4.debian.tar.xz
 aff74106091cfab23baa180968e5d15e41ade4e3 8548 rsyslog_8.2608.0-4_source.buildinfo
Checksums-Sha256:
 43f1d232c07f92a26a7bdd1f541cb0cba3aaaba75edab7f6a017f0719f231202 3796 rsyslog_8.2608.0-4.dsc
 8c8fcca722c9a9d303087fc1efacf8c15d537c068079b908eff901253156f109 35948 rsyslog_8.2608.0-4.debian.tar.xz
 b742eb032b75be7b8b9fbe05ee4e5a9f8796fe638a8be3408878a039f6f23733 8548 rsyslog_8.2608.0-4_source.buildinfo
Files:
 920233851c0b808c13aaf6763dbe579b 3796 admin optional rsyslog_8.2608.0-4.dsc
 86e37c8c22ee32fb06e923f698779d90 35948 admin optional rsyslog_8.2608.0-4.debian.tar.xz
 645a18a6d2319942c0a2f51dacc6eed7 8548 admin optional rsyslog_8.2608.0-4_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEECbOsLssWnJBDRcxUauHfDWCPItwFAmqTcj8ACgkQauHfDWCP
Itz2Aw//Wk1CRn4HMF8K5ktUaiAuBCntNMUZ4zSa36V6tQa9Px8IPiazeTEptWkj
088CPoq5YvRStpRmixduYDsqbB0wKFHAD+9y7Ta1EIARemuke9wL3hgTHq4sSgKk
KpsHET+r8ygxtYKosAPbge7kgMdIcj7+E28bZ5Z1JyU1Oq8bcV12IbxY0CcKPF4K
0vjauStSk1Iiw1XgiBZ4cbV0KmAcctZ4kzc5NfYMbggDRx1MHhqvM7RwwIZHIi26
+vsDq0+aUzXRpSuC1EWQtd+cLS0QFZjvSxt37NpObgrKl+jP1CEXtfToghy6hMRG
9oMTOWqaV/nEvsGGvwgdLYpJ6L6XYmVaWsIDJgQoybJ6rGkMAFX00TLzIPtzsyJ4
PJMRArgNDnENx/RbgR6V5wjbWsUADpRjDrK4ZCUIsGEKvt4gBRsA0uxVH33syZ8M
BNr8lnvWcDteeaPOgaHtTkIaplaRhm3cEtUxKjFTm964mJzPofBXoPuaaum3qZg/
kGIX0WLy1ae0NhZTJxd1STuWrF9j7GLphR0DS74u/8lrPmDtc1gHfC4pFBEla7RJ
i4m/pnf9KpyvPkZfK5vfkQzd6LkYsnIwr6yzfMkP/8WJWN9vC85iCnrKbrOzeLXk
cnngsynH3JHn+5BBDaznHiDSsM8XYzDEB0w4lBMpP+Y6pw5sLqI=
=KFJR
-----END PGP SIGNATURE-----

#1145980#43
Date:
2026-08-30 00:33:22 UTC
From:
To:
Am 29.08.26 um 06:43 schrieb Salvatore Bonaccorso:

Done.
See https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145386

I had already uploaded a 8.2504.0-1+deb13u1 to stable-proposed-updates
so made a subsequent 8.2504.0-1+deb13u2

Regards,
Michael

#1145980#48
Date:
2026-08-31 17:17:06 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
rsyslog, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145980@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Biebl <biebl@debian.org> (supplier of updated rsyslog package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 30 Aug 2026 02:19:20 +0200
Source: rsyslog
Architecture: source
Version: 8.2504.0-1+deb13u2
Distribution: trixie
Urgency: medium
Maintainer: Michael Biebl <biebl@debian.org>
Changed-By: Michael Biebl <biebl@debian.org>
Closes: 1145980
Changes:
 rsyslog (8.2504.0-1+deb13u2) trixie; urgency=medium
 .
   * rainerscript: Avoid heap buffer overflow in replace() function.
     Patch cherry-picked from upstream Git.
     (CVE-2026-78002, Closes: #1145980)
   * mmpstrucdata: Fix stack buffer overflow with oversized RFC5424 structured
     data.
     Patch backported from upstream Git.
     (CVE-2026-61548)
Checksums-Sha1:
 b02febd55175496bb261e32563841936a6bbdde9 3452 rsyslog_8.2504.0-1+deb13u2.dsc
 078be15a246f30f660c0a5bf9f6cd0cdb7b7b886 35252 rsyslog_8.2504.0-1+deb13u2.debian.tar.xz
 72e77b9fb34b04de8f0fbd14532a57b29ed23779 7900 rsyslog_8.2504.0-1+deb13u2_source.buildinfo
Checksums-Sha256:
 8afcb5ca46e18a77e3151d66abba1313df4a9202cbc67e467344ce9c4ffe698b 3452 rsyslog_8.2504.0-1+deb13u2.dsc
 2ffeac2e399343e9de0c0148a015a335545fff37e02d66be0d17a60bd279f995 35252 rsyslog_8.2504.0-1+deb13u2.debian.tar.xz
 bcfa023991bf6f9c0c05fe2069ec36e64ec79c5887b68330ca2923bdf83ecf02 7900 rsyslog_8.2504.0-1+deb13u2_source.buildinfo
Files:
 ad6567ee7039701acd2d67a0570a318d 3452 admin optional rsyslog_8.2504.0-1+deb13u2.dsc
 5636acf3323553fa68816ea37869bad0 35252 admin optional rsyslog_8.2504.0-1+deb13u2.debian.tar.xz
 585f5a7abfbd4d77edaeb9c3dc7fa483 7900 admin optional rsyslog_8.2504.0-1+deb13u2_source.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEECbOsLssWnJBDRcxUauHfDWCPItwFAmqTeLMACgkQauHfDWCP
ItzlcQ//als9jGxljrm4Y/fZvaJjIhNoKQp0WcPlv37AREDwIn99RxEalCoqj5rK
PwjuDzxAxHxODiQ/0xDHmEjyixEZ5v2VnblqlYY4Ryzh8473p2KWiX5WhGVHytFO
EbSb7EQsLv3m1HnHrSjbw4PxPpuZ3N3dm9L3ImlPD1VP2omTwLi10FF9w+nfmthH
TwJuxIjw9um00E4ZgLS6qi+mCMq3GTyPjd11cb1tzaRiF/BGtL87ixdXrWRTLv/G
bRCvgiuOcnTB4/cKehzMEHopnEuJUTpb6frgjZUE6Bf8fDuz6JEKeqDvcqM+Rt2i
m38snctm9pY14ioqd8xjXATlY7B+UutJgakhZg7X8FrCy+RVuR3V4apsejH5pRKh
ZYSZ12p9z8xyITcGAiMgCp5QaPoqjNHiJYCIPa4n0a8VifJ+yd/bNsXbc/KKivi5
wtVjmfAdbx0AkV5+0Eo34Eh8q8GLr2nh0HiEudmHOJTSZ/dbN8d/kbWcEgUNrLS3
YQ7IdMgoLGKnziUXv7oyoRm2QPET0GwxThs6PIkWwRb+AwbuW69lmv7OxplJ7oz/
mY4TjLtRcGSDWFiaq6ScrguKmGxXw5ThJhRoB2FBC1+IuXKaCavXQ6VjdeErizJ7
cSu5KuBKoohaa8RS+3yHz5T+9+2MjmeXi6c6lO7fFC/ojaTkHuA=
=Pj32
-----END PGP SIGNATURE-----