Sceawere

Vulnerability Detail

CVE-2026-19654UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

rsyslogd imptcp Oversize Frame Denial of Service

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
Red Hat
Product
Red Hat Enterprise Linux 10
Attack Type
Out-of-bounds Read
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-12T21:17:38.517Z",
  "pubdate": "2026-08-12T21:17:38.517Z",
  "executiveSummary": "An availability vulnerability exists within the optional imptcp module of rsyslogd, allowing an unauthenticated remote peer to cause a daemon crash.\nThe vulnerability is triggered by a crafted input sequence during oversize-frame recovery, which results in an invalid internal message length calculation and subsequent termination of the rsyslogd service.\nThe affected product is rsyslogd, specifically when utilizing the optional imptcp module. Standard configurations utilizing imtcp and the default imptcp framing modes are not affected.\nThe risk implication is a denial of service (DoS) affecting centralized logging infrastructure, potentially impairing security monitoring and event tracking capabilities.\nAn attacker must possess network access to the target listening port of the optional imptcp module, but no authentication, privileges, or prior system access are required.\nThere is no identified impact on confidentiality or integrity, and the vulnerability does not allow for privilege escalation or remote code execution.",
  "technicalDetails": "The vulnerability resides in the optional imptcp module of rsyslogd, specifically within the framing and buffer management logic handling incoming TCP syslog streams.\nThe root cause is an improper handling of message length calculations during the oversize-frame recovery state. When an incoming frame exceeds predefined size limits, the recovery mechanism processes a crafted input sequence in a manner that computes an invalid internal message length.\nExploitation requires network exposure to the port bound by the optional imptcp module. The attacker does not require authentication or elevated privileges, as the listener accepts unauthenticated remote connections.\nThe attack flow proceeds as follows: 1. The remote attacker establishes a TCP connection to the rsyslogd instance running the vulnerable imptcp module. 2. The attacker transmits a specially crafted input sequence designed to trigger an oversize-frame condition. 3. Upon encountering the oversize frame, the module initiates its error recovery routine. 4. Due to flawed logic in the recovery state, the internal message length is calculated incorrectly. 5. The invalid length value triggers a fatal error or assertion failure, forcing the rsyslogd process to terminate immediately, resulting in a denial of service.\nPayload behavior is limited to causing process termination; no arbitrary code execution, memory disclosure, or data modification occurs.\nPost-exploitation impact is constrained exclusively to service availability. The crash halts log collection until the service is manually or automatically restarted by a process supervisor."
}
CVE-2026-19654: rsyslogd imptcp Oversize Frame Denial of Service (HIGH Severity, CVSS: 7.5) - Sceawere