rpm package
almalinux/rsyslog-mmnormalize
pkg:rpm/almalinux/rsyslog-mmnormalize
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-78002 | Hig | 7.5 | < 8.2510.0-2.el9_8.2 | 8.2510.0-2.el9_8.2 | Aug 27, 2026 | A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, | |
| CVE-2026-19654 | Hig | 7.5 | < 8.2510.0-2.el9_8.1 | 8.2510.0-2.el9_8.1 | Aug 12, 2026 | A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege esc | |
| CVE-2022-24903 | Hig | 8.1 | < 8.2102.0-7.el8 | 8.2102.0-7.el8 | May 6, 2022 | Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for |
- affected < 8.2510.0-2.el9_8.2fixed 8.2510.0-2.el9_8.2
A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement,
- affected < 8.2510.0-2.el9_8.1fixed 8.2510.0-2.el9_8.1
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege esc
- affected < 8.2102.0-7.el8fixed 8.2102.0-7.el8
Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for