CVE-2026-19654
Publication date 13 August 2026
Last updated 18 August 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| rsyslog | 26.04 LTS resolute |
Fixed 8.2512.0-1ubuntu4.1
|
| 24.04 LTS noble |
Fixed 8.2312.0-3ubuntu9.3
|
|
| 22.04 LTS jammy |
Fixed 8.2112.0-2ubuntu2.4
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
Notes
mdeslaur
The fix for this issue was included in USN-8598-1 but the CVE number wasn't available at time of publication
Patch details
| Package | Patch details |
|---|---|
| rsyslog |
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
7.5 · High
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H