Your message dated Sun, 30 Aug 2026 00:18:54 +0000
with message-id <[email protected]>
and subject line Bug#1145980: fixed in rsyslog 8.2608.0-4
has caused the Debian Bug report #1145980,
regarding rsyslog: CVE-2026-78002
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1145980: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145980
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: rsyslog
Version: 8.2608.0-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for rsyslog.

CVE-2026-78002[0]:
| A flaw was found in rsyslog. An unauthenticated remote attacker can
| trigger a heap buffer overflow in the RainerScript `replace()`
| function by sending specially crafted syslog messages. This
| vulnerability arises from an incorrect buffer size calculation
| during string replacement, causing memory corruption. Successful
| exploitation can lead to a denial of service (DoS) for the affected
| system.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-78002
    https://www.cve.org/CVERecord?id=CVE-2026-78002
[1] https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: rsyslog
Source-Version: 8.2608.0-4
Done: Michael Biebl <[email protected]>

We believe that the bug you reported is fixed in the latest version of
rsyslog, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Biebl <[email protected]> (supplier of updated rsyslog package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 30 Aug 2026 01:58:01 +0200
Source: rsyslog
Architecture: source
Version: 8.2608.0-4
Distribution: unstable
Urgency: medium
Maintainer: Michael Biebl <[email protected]>
Changed-By: Michael Biebl <[email protected]>
Closes: 1145980
Changes:
 rsyslog (8.2608.0-4) unstable; urgency=medium
 .
   * rainerscript: Avoid heap buffer overflow in replace() function.
     Patch cherry-picked from upstream Git.
     (CVE-2026-78002, Closes: #1145980)
Checksums-Sha1:
 3aafb44a09f4beea2e5a9ef8ec0232c1e53aad4c 3796 rsyslog_8.2608.0-4.dsc
 92b850a2da4d6165870b02e77b3d4eca3056fd2a 35948 rsyslog_8.2608.0-4.debian.tar.xz
 aff74106091cfab23baa180968e5d15e41ade4e3 8548 
rsyslog_8.2608.0-4_source.buildinfo
Checksums-Sha256:
 43f1d232c07f92a26a7bdd1f541cb0cba3aaaba75edab7f6a017f0719f231202 3796 
rsyslog_8.2608.0-4.dsc
 8c8fcca722c9a9d303087fc1efacf8c15d537c068079b908eff901253156f109 35948 
rsyslog_8.2608.0-4.debian.tar.xz
 b742eb032b75be7b8b9fbe05ee4e5a9f8796fe638a8be3408878a039f6f23733 8548 
rsyslog_8.2608.0-4_source.buildinfo
Files:
 920233851c0b808c13aaf6763dbe579b 3796 admin optional rsyslog_8.2608.0-4.dsc
 86e37c8c22ee32fb06e923f698779d90 35948 admin optional 
rsyslog_8.2608.0-4.debian.tar.xz
 645a18a6d2319942c0a2f51dacc6eed7 8548 admin optional 
rsyslog_8.2608.0-4_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEECbOsLssWnJBDRcxUauHfDWCPItwFAmqTcj8ACgkQauHfDWCP
Itz2Aw//Wk1CRn4HMF8K5ktUaiAuBCntNMUZ4zSa36V6tQa9Px8IPiazeTEptWkj
088CPoq5YvRStpRmixduYDsqbB0wKFHAD+9y7Ta1EIARemuke9wL3hgTHq4sSgKk
KpsHET+r8ygxtYKosAPbge7kgMdIcj7+E28bZ5Z1JyU1Oq8bcV12IbxY0CcKPF4K
0vjauStSk1Iiw1XgiBZ4cbV0KmAcctZ4kzc5NfYMbggDRx1MHhqvM7RwwIZHIi26
+vsDq0+aUzXRpSuC1EWQtd+cLS0QFZjvSxt37NpObgrKl+jP1CEXtfToghy6hMRG
9oMTOWqaV/nEvsGGvwgdLYpJ6L6XYmVaWsIDJgQoybJ6rGkMAFX00TLzIPtzsyJ4
PJMRArgNDnENx/RbgR6V5wjbWsUADpRjDrK4ZCUIsGEKvt4gBRsA0uxVH33syZ8M
BNr8lnvWcDteeaPOgaHtTkIaplaRhm3cEtUxKjFTm964mJzPofBXoPuaaum3qZg/
kGIX0WLy1ae0NhZTJxd1STuWrF9j7GLphR0DS74u/8lrPmDtc1gHfC4pFBEla7RJ
i4m/pnf9KpyvPkZfK5vfkQzd6LkYsnIwr6yzfMkP/8WJWN9vC85iCnrKbrOzeLXk
cnngsynH3JHn+5BBDaznHiDSsM8XYzDEB0w4lBMpP+Y6pw5sLqI=
=KFJR
-----END PGP SIGNATURE-----

Attachment: pgp4gvTkAXctH.pgp
Description: PGP signature


--- End Message ---

Reply via email to