CVE-2026-19654
Received Received - Intake

Unauthenticated DoS in rsyslog via imptcp Module

Vulnerability report for CVE-2026-19654, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-12

Last updated on: 2026-08-12

Assigner: Red Hat, Inc.

Description

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-12
Last Modified
2026-08-12
Generated
2026-08-13
AI Q&A
2026-08-13
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rsyslog rsyslogd *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an unauthenticated remote peer to crash the rsyslogd service by exploiting a flaw in the optional imptcp module. A specially crafted input sequence during oversize-frame recovery can cause an invalid internal message length, leading to termination of rsyslogd. The default imtcp and imptcp framing modes are not affected.

Detection Guidance

This vulnerability can be detected by checking if the imptcp module is enabled in rsyslogd and monitoring for crashes. Inspect rsyslog configuration files for imptcp module usage and review logs for abnormal terminations of rsyslogd.

Impact Analysis

The impact is limited to service disruption. The vulnerability causes rsyslogd to crash, which may result in loss of logging functionality. There is no impact on confidentiality, integrity, privilege escalation, or code execution.

Compliance Impact

This vulnerability may affect compliance by disrupting logging capabilities, which are often required for audit trails and monitoring under standards like GDPR and HIPAA. However, since it does not impact confidentiality or integrity, the primary concern is operational disruption rather than data exposure.

Mitigation Strategies

Disable the imptcp module in rsyslogd if it is enabled. Update rsyslog to the latest version that patches this flaw. Monitor rsyslogd for crashes and ensure no oversize-frame recovery issues occur.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19654. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart