CVE-2026-61548
Publication date 20 July 2026
Last updated 23 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer and calls parsePARAM_VALUE without supplying the destination size. A remote unauthenticated attacker whose crafted RFC5424 message reaches an action using mmpstrucdata can provide a structured-data parameter larger than that buffer when MaxMessageSize permits it, causing an attacker-controlled stack overwrite. Deployments that do not install and use the plugin, or whose effective message-size limit remains below the required threshold, are not affected by this issue. The demonstrated impact is a crash and interruption of log collection; code execution is not demonstrated. This issue is fixed in version 8.2606.0.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| rsyslog | 26.04 LTS resolute |
Fixed 8.2512.0-1ubuntu4.1
|
| 24.04 LTS noble |
Fixed 8.2312.0-3ubuntu9.3
|
|
| 22.04 LTS jammy |
Fixed 8.2112.0-2ubuntu2.4
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
Severity score breakdown
CVSS version: CVSS v3.0
Base score
8.1 · High
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
References
Related Ubuntu Security Notices (USN)
- USN-8598-1
- rsyslog vulnerabilities
- 23 July 2026