Status: UPDATED | Advisory ID: CVE-2026-19654
| CVE | CVE-2026-19654 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-09-24 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high. |
| Affected products | see table below |
| Classified as | CWE-125 (Out-of-bounds Read) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Red Hat | Enterprise Linux | ||
| Red Hat | Red Hat Enterprise Linux 10 | ||
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | ||
| Red Hat | Red Hat Enterprise Linux 8 | ||
| Red Hat | Red Hat Enterprise Linux 9 | ||
| Red Hat | Red Hat Update Infrastructure 5 | ||
| rsyslog | rsyslog |
| Subsystems | EWS Workstation Delivery/Virtualization |
| Sectors | All Sectors |
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected. (NVD)
Monitor Red Hat's and rsyslog's web pages for any future patch releases. See vendor advisory link below.