Your message dated Mon, 31 Aug 2026 17:17:06 +0000
with message-id <[email protected]>
and subject line Bug#1145980: fixed in rsyslog 8.2504.0-1+deb13u2
has caused the Debian Bug report #1145980,
regarding rsyslog: CVE-2026-78002
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1145980: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145980
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: rsyslog
Version: 8.2608.0-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for rsyslog.

CVE-2026-78002[0]:
| A flaw was found in rsyslog. An unauthenticated remote attacker can
| trigger a heap buffer overflow in the RainerScript `replace()`
| function by sending specially crafted syslog messages. This
| vulnerability arises from an incorrect buffer size calculation
| during string replacement, causing memory corruption. Successful
| exploitation can lead to a denial of service (DoS) for the affected
| system.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-78002
    https://www.cve.org/CVERecord?id=CVE-2026-78002
[1] https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: rsyslog
Source-Version: 8.2504.0-1+deb13u2
Done: Michael Biebl <[email protected]>

We believe that the bug you reported is fixed in the latest version of
rsyslog, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Biebl <[email protected]> (supplier of updated rsyslog package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 30 Aug 2026 02:19:20 +0200
Source: rsyslog
Architecture: source
Version: 8.2504.0-1+deb13u2
Distribution: trixie
Urgency: medium
Maintainer: Michael Biebl <[email protected]>
Changed-By: Michael Biebl <[email protected]>
Closes: 1145980
Changes:
 rsyslog (8.2504.0-1+deb13u2) trixie; urgency=medium
 .
   * rainerscript: Avoid heap buffer overflow in replace() function.
     Patch cherry-picked from upstream Git.
     (CVE-2026-78002, Closes: #1145980)
   * mmpstrucdata: Fix stack buffer overflow with oversized RFC5424 structured
     data.
     Patch backported from upstream Git.
     (CVE-2026-61548)
Checksums-Sha1:
 b02febd55175496bb261e32563841936a6bbdde9 3452 rsyslog_8.2504.0-1+deb13u2.dsc
 078be15a246f30f660c0a5bf9f6cd0cdb7b7b886 35252 
rsyslog_8.2504.0-1+deb13u2.debian.tar.xz
 72e77b9fb34b04de8f0fbd14532a57b29ed23779 7900 
rsyslog_8.2504.0-1+deb13u2_source.buildinfo
Checksums-Sha256:
 8afcb5ca46e18a77e3151d66abba1313df4a9202cbc67e467344ce9c4ffe698b 3452 
rsyslog_8.2504.0-1+deb13u2.dsc
 2ffeac2e399343e9de0c0148a015a335545fff37e02d66be0d17a60bd279f995 35252 
rsyslog_8.2504.0-1+deb13u2.debian.tar.xz
 bcfa023991bf6f9c0c05fe2069ec36e64ec79c5887b68330ca2923bdf83ecf02 7900 
rsyslog_8.2504.0-1+deb13u2_source.buildinfo
Files:
 ad6567ee7039701acd2d67a0570a318d 3452 admin optional 
rsyslog_8.2504.0-1+deb13u2.dsc
 5636acf3323553fa68816ea37869bad0 35252 admin optional 
rsyslog_8.2504.0-1+deb13u2.debian.tar.xz
 585f5a7abfbd4d77edaeb9c3dc7fa483 7900 admin optional 
rsyslog_8.2504.0-1+deb13u2_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEECbOsLssWnJBDRcxUauHfDWCPItwFAmqTeLMACgkQauHfDWCP
ItzlcQ//als9jGxljrm4Y/fZvaJjIhNoKQp0WcPlv37AREDwIn99RxEalCoqj5rK
PwjuDzxAxHxODiQ/0xDHmEjyixEZ5v2VnblqlYY4Ryzh8473p2KWiX5WhGVHytFO
EbSb7EQsLv3m1HnHrSjbw4PxPpuZ3N3dm9L3ImlPD1VP2omTwLi10FF9w+nfmthH
TwJuxIjw9um00E4ZgLS6qi+mCMq3GTyPjd11cb1tzaRiF/BGtL87ixdXrWRTLv/G
bRCvgiuOcnTB4/cKehzMEHopnEuJUTpb6frgjZUE6Bf8fDuz6JEKeqDvcqM+Rt2i
m38snctm9pY14ioqd8xjXATlY7B+UutJgakhZg7X8FrCy+RVuR3V4apsejH5pRKh
ZYSZ12p9z8xyITcGAiMgCp5QaPoqjNHiJYCIPa4n0a8VifJ+yd/bNsXbc/KKivi5
wtVjmfAdbx0AkV5+0Eo34Eh8q8GLr2nh0HiEudmHOJTSZ/dbN8d/kbWcEgUNrLS3
YQ7IdMgoLGKnziUXv7oyoRm2QPET0GwxThs6PIkWwRb+AwbuW69lmv7OxplJ7oz/
mY4TjLtRcGSDWFiaq6ScrguKmGxXw5ThJhRoB2FBC1+IuXKaCavXQ6VjdeErizJ7
cSu5KuBKoohaa8RS+3yHz5T+9+2MjmeXi6c6lO7fFC/ojaTkHuA=
=Pj32
-----END PGP SIGNATURE-----

Attachment: pgpjUxcoItqOj.pgp
Description: PGP signature


--- End Message ---

Reply via email to