PatchSiren cyber security CVE debrief
CVE-2026-19654 Red Hat CVE debrief
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. This vulnerability affects the rsyslogd service, which is commonly used for system logging. The HIGH CVSS score of 7.5 indicates a high severity, and the potential for denial of service requires prompt attention from affected operators and security teams. System administrators and security teams should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should prioritize patching or mitigating this vulnerability to prevent potential denial-of-service attacks. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-12
- Original CVE updated
- 2026-08-25
- Advisory published
- 2026-08-12
- Advisory updated
- 2026-08-25
Who should care
System administrators and security teams responsible for managing rsyslogd installations, particularly in environments where remote access to rsyslogd is possible, should prioritize patching or mitigating this vulnerability. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems while remediation is scheduled and verified. Additionally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. The HIGH CVSS score of 7.5 indicates a high severity, and the potential for denial of service requires prompt attention from affected operators and security teams.
Technical summary
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. This vulnerability has a HIGH CVSS score of 7.5, indicating a high severity. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected. The vulnerability affects the rsyslogd service, which is commonly used for system logging. Affected system administrators and security teams should prioritize patching or mitigating this vulnerability to prevent potential denial-of-service attacks.
Defensive priority
High-priority defensive actions are recommended due to the HIGH CVSS score of 7.5 and potential for denial of service.
Recommended defensive actions
- Apply vendor patches or updates to address the vulnerability
- Restrict access to the rsyslogd service to prevent unauthorized access
- Monitor rsyslogd logs for potential exploitation attempts
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The evidence for this CVE is based on the NVD CVE record and related references. The CVE record indicates a flaw in the optional imptcp module of rsyslogd that can cause a crash due to an invalid internal message length. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. However, the HIGH CVSS score of 7.5 indicates a significant potential for denial of service. Defenders should verify the affected product deployments, review official advisories, and plan vendor-supported updates or mitigations. They should also monitor rsyslogd logs for potential exploitation attempts and review compensating controls for exposed systems.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19654 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19654
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19654 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19654
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-19654
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.