Control: found -1 8.6.0-1
Control: fixed -1 8.2608.0-1

Hi Salvatore

Am 28.08.26 um 16:06 schrieb Salvatore Bonaccorso:

The following vulnerability was published for rsyslog.

CVE-2026-78002[0]:
| A flaw was found in rsyslog. An unauthenticated remote attacker can
| trigger a heap buffer overflow in the RainerScript `replace()`
| function by sending specially crafted syslog messages. This
| vulnerability arises from an incorrect buffer size calculation
| during string replacement, causing memory corruption. Successful
| exploitation can lead to a denial of service (DoS) for the affected
| system.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-78002
     https://www.cve.org/CVERecord?id=CVE-2026-78002
[1] https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3

Please adjust the affected versions in the BTS as needed.

I've adjusted according to the upstream version information at [1]

Do you want me to fix that via stable or stable-security?



Regards,
Michael

Attachment: OpenPGP_signature.asc
Description: OpenPGP digital signature

Reply via email to