Source: rsyslog
Version: 8.2608.0-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for rsyslog.

CVE-2026-78002[0]:
| A flaw was found in rsyslog. An unauthenticated remote attacker can
| trigger a heap buffer overflow in the RainerScript `replace()`
| function by sending specially crafted syslog messages. This
| vulnerability arises from an incorrect buffer size calculation
| during string replacement, causing memory corruption. Successful
| exploitation can lead to a denial of service (DoS) for the affected
| system.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-78002
    https://www.cve.org/CVERecord?id=CVE-2026-78002
[1] https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to