๐Ÿ” CVE Alert

CVE-2026-61548

HIGH 8.1

Rsyslog: mmpstrucdata stack buffer overflow with oversized RFC5424 structured data

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer and calls parsePARAM_VALUE without supplying the destination size. A remote unauthenticated attacker whose crafted RFC5424 message reaches an action using mmpstrucdata can provide a structured-data parameter larger than that buffer when MaxMessageSize permits it, causing an attacker-controlled stack overwrite. Deployments that do not install and use the plugin, or whose effective message-size limit remains below the required threshold, are not affected by this issue. The demonstrated impact is a crash and interruption of log collection; code execution is not demonstrated. This issue is fixed in version 8.2606.0.

CWE CWE-121
Vendor rsyslog
Product rsyslog
Published Sep 18, 2026
Last Updated Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for rsyslog rsyslog

Be the first to know when new high vulnerabilities affecting rsyslog rsyslog are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

rsyslog / rsyslog
>= 7.5.4, < 8.2606.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-8qmr-c66f-g368 github.com: https://github.com/rsyslog/rsyslog/pull/6991 github.com: https://github.com/rsyslog/rsyslog/commit/bcda60a3692efdf0c8e44102528f5a0ebe0dec6d github.com: https://github.com/rsyslog/rsyslog/releases/tag/v8.2606.0 openwall.com: http://www.openwall.com/lists/oss-security/2026/07/20/1