← All Advisories

CVE-2026-19654

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-19654

Key Details

CVECVE-2026-19654
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productssee table below
Classified asCWE-125 (Out-of-bounds Read)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
Red HatEnterprise Linux
Red HatRed Hat Enterprise Linux 10
Red HatRed Hat Enterprise Linux 10.0 Extended Update Support
Red HatRed Hat Enterprise Linux 8
Red HatRed Hat Enterprise Linux 9
Red HatRed Hat Update Infrastructure 5
rsyslogrsyslog
SubsystemsEWS Workstation Delivery/Virtualization
SectorsAll Sectors

What to Know

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected. (NVD)

What to Do

Monitor Red Hat's and rsyslog's web pages for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-19654
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-19654
Vendor advisoryhttps://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29