DEBIAN-CVE-2026-61548

Source
https://security-tracker.debian.org/tracker/CVE-2026-61548
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-61548.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-61548
Upstream
Published
2026-09-18T17:16:58Z
Modified
2026-09-19T05:00:11Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer and calls parsePARAM_VALUE without supplying the destination size. A remote unauthenticated attacker whose crafted RFC5424 message reaches an action using mmpstrucdata can provide a structured-data parameter larger than that buffer when MaxMessageSize permits it, causing an attacker-controlled stack overwrite. Deployments that do not install and use the plugin, or whose effective message-size limit remains below the required threshold, are not affected by this issue. The demonstrated impact is a crash and interruption of log collection; code execution is not demonstrated. This issue is fixed in version 8.2606.0.

References

Affected packages

Debian:12 / rsyslog

Package

Name
rsyslog
Purl
pkg:deb/debian/rsyslog?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

8.*
8.2302.0-1
8.2302.0-1+deb12u1
8.2304.0-1
8.2306.0-1
8.2306.0-2
8.2308.0-1
8.2310.0-1
8.2310.0-2
8.2310.0-3
8.2310.0-4
8.2312.0-1
8.2312.0-2
8.2312.0-3
8.2402.0-1
8.2404.0-1
8.2404.0-2
8.2406.0-1
8.2408.0-1
8.2408.0-2
8.2410.0-1
8.2412.0-1
8.2412.0-2
8.2502.0-1
8.2502.0-2
8.2502.0-3
8.2502.0-4
8.2502.0-5
8.2502.0-6
8.2504.0-1
8.2506.0-1
8.2506.0-2
8.2506.0-3
8.2506.0-4
8.2506.0-6
8.2510.0-1
8.2510.0-2
8.2510.0-3
8.2510.0-4
8.2510.0-5
8.2512.0-1
8.2512.0-2
8.2512.0-3
8.2602.0-1
8.2604.0-1
8.2604.0-2
8.2604.0-3
8.2604.0-4
8.2606.0-1
8.2606.0-2
8.2606.0-3
8.2606.0-4
8.2608.0-1
8.2608.0-2
8.2608.0-3
8.2608.0-4

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-61548.json"

Debian:13 / rsyslog

Package

Name
rsyslog
Purl
pkg:deb/debian/rsyslog?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.2504.0-1+deb13u2

Affected versions

8.*
8.2504.0-1
8.2504.0-1+deb13u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-61548.json"

Debian:14 / rsyslog

Package

Name
rsyslog
Purl
pkg:deb/debian/rsyslog?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8.2606.0-4

Affected versions

8.*
8.2504.0-1
8.2506.0-1
8.2506.0-2
8.2506.0-3
8.2506.0-4
8.2506.0-6
8.2510.0-1
8.2510.0-2
8.2510.0-3
8.2510.0-4
8.2510.0-5
8.2512.0-1
8.2512.0-2
8.2512.0-3
8.2602.0-1
8.2604.0-1
8.2604.0-2
8.2604.0-3
8.2604.0-4
8.2606.0-1
8.2606.0-2
8.2606.0-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-61548.json"