---
id: CVE-2026-19654
title: >-
  A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the
  optional imptcp module
summary: >-
  A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the
  optional imptcp module. A crafted input sequence during oversize-frame
  recovery can cause an invalid internal message length and terminate rsyslogd.
  No confide…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
vendor: rsyslog
product: rsyslog
affected:
  - 'rsyslog >= 8.36.0, < 8.2608.0'
  - enterprise_linux = 6.0
  - enterprise_linux = 7.0
  - enterprise_linux = 8.0
  - enterprise_linux = 9.0
  - enterprise_linux = 10.0
patched:
  - rsyslog 8.2608.0
published: '2026-08-12'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T17:17:04.370'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19654'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2026:66405'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:67583'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:67584'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2026:71603'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2026-19654'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2502868'
    label: secalert@redhat.com
  - url: 'https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29'
    label: secalert@redhat.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19654.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-19654'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-19654'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.00466
epssPercentile: 0.3766
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-08-13T12:58:34.167792Z'
ingestedAt: '2026-09-10T14:51:56.267Z'
---

## Overview

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.

## Affected

- `rsyslog >= 8.36.0, < 8.2608.0`
- `enterprise_linux = 6.0`
- `enterprise_linux = 7.0`
- `enterprise_linux = 8.0`
- `enterprise_linux = 9.0`
- `enterprise_linux = 10.0`

## Remediation

Upgrade past the affected range:

- `rsyslog 8.2608.0`

## Vendor advisories

- **RHSA-2026:66405** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66405)
- **Red Hat VEX** · Important · affected: Red Hat Enterprise Linux 8 · no fix planned: Red Hat Enterprise Linux 8 · updated 2026-09-24 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-19654.json)
- **RHSA-2026:67584** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67584)
- **RHSA-2026:67583** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2026:67583)
- **RHSA-2026:71603** · Red Hat · fixed in: Red Hat Update Infrastructure 5 · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71603)
