Skip to content
Red HatCVE-2026-78002

Red Hat rsyslog: buffer overflow

High7.5CVE-2026-78002 · Published Aug 27, 2026 · updated Sep 25, 2026

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.

Red Hat advisory

Affected versions

PackageAffectedFixed in
Red Hat Enterprise Linux 6
Product
all versionsNo fix yet
all versionsNo fix yet
Red Hat Enterprise Linux 7
Product
all versionsNo fix yet
Red Hat Enterprise Linux 8
Product
all versionsNo fix yet
Details and references

More Red Hat advisories

All Red Hat
Advisory
Red Hat gdk-pixbuf.: out-of-bounds write
Medium4.7Aug 27
Red Hat Undertow. A remote attacker: resource exhaustion
High7.5Aug 27
Red Hat Satellite 6: insecure direct object reference
Medium6.5Aug 27
Red Hat Satellite 6: insecure direct object reference
Medium5.4Aug 27
A flaw was found in the ipa_getkeytab module of the community.general Ansible...
Medium5.5Aug 26
Red Hat Seattle FilmWorks plugin: integer overflow
Medium5.5Aug 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.