Release date:
2026-09-01 11:39:02 UTC
Description:
* SECURITY UPDATE: denial of service in the optional imptcp module: a regex match at offset zero after oversize-frame recovery submits a negative message length and crashes rsyslogd
- debian/patches/CVE-2026-19654.patch: denial of service in the optional imptcp module: a regex match at offset zero after oversize-frame recovery submits a negative message length and crashes rsyslogd
- CVE-2026-19654
* debian/patches/Skip-tests-that-cannot-run-in-the-build-environment.patch:
skip omfile-read-only, omfile-read-only-errmsg, privdropuser and
privdropuserid. All four fail in the pdebuild chroot for reasons
unrelated to rsyslog (root bypasses the 0400 mode the first two rely
on; the chroot has no unprivileged test user for the last two), and
they fail identically on the unpatched vendor sources.
Updated packages:
-
rsyslog_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:71173699bdc01937849908dd719dd2865a3c4832
-
rsyslog-czmq_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:1b2c578ab43af702c51bdaa40949025763c0a29c
-
rsyslog-elasticsearch_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:cf85135ab9cf92e3795c8a5b25da2ee0c89ac8c5
-
rsyslog-gnutls_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:52368389dac12b497b79d6bee3c22c53819f30ce
-
rsyslog-gssapi_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:ced28ef5f2e01bc45c216d3edc50a52f952c533d
-
rsyslog-hiredis_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:408b996ffe4b70e6056127f80d31adb6c9703a99
-
rsyslog-kafka_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:092361690a609f95a06970354c4b437f7e9295e8
-
rsyslog-mongodb_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:288a184b72f2030a0a6adcd9408b6d8453498943
-
rsyslog-mysql_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:8d279ed2c46d9e491dfbf1f4149af5ca2403394b
-
rsyslog-pgsql_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:ba01d9cdaa9d9d7fdde3648bcf399dd98139db52
-
rsyslog-relp_8.1901.0-1+deb10u2+tuxcare.els1_amd64.deb
sha:7df1dd22e45526eb317dd76dbbd1aa02f01a9a7e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.