CVE-2026-61548
Description
Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer and calls parsePARAM_VALUE without supplying the destination size. A remote unauthenticated attacker whose crafted RFC5424 message reaches an action using mmpstrucdata can provide a structured-data parameter larger than that buffer when MaxMessageSize permits it, causing an attacker-controlled stack overwrite. Deployments that do not install and use the plugin, or whose effective message-size limit remains below the required threshold, are not affected by this issue. The demonstrated impact is a crash and interruption of log collection; code execution is not demonstrated. This issue is fixed in version 8.2606.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- osv-coords2 versionspkg:rpm/opensuse/rsyslog&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/rsyslog&distro=openSUSE%20Leap%2016.0
< 8.2606.0-1.1+ 1 more
- (no CPE)range: < 8.2606.0-1.1
- (no CPE)range: < 8.2502.0-160000.4.1
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.