CVE-2026-19654
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.42% probability · 36th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- rsyslog/rsyslog · redhat/enterprise linux
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2026:66405
- https://access.redhat.com/security/cve/CVE-2026-19654Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2502868Issue Tracking, Third Party Advisory
- https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.