Your message dated Mon, 31 Aug 2026 17:17:05 +0000
with message-id <[email protected]>
and subject line Bug#1144616: fixed in rsyslog 8.2504.0-1+deb13u1
has caused the Debian Bug report #1144616,
regarding rsyslog: CVE-2026-19654
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1144616: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1144616
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: rsyslog
Version: 8.2606.0-4
Severity: important
Tags: security upstream
Forwarded: https://github.com/rsyslog/rsyslog/pull/7410
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for rsyslog.

CVE-2026-19654[0]:
| A unauthenticated remote peer may lead rsyslogd to crash due to a
| flaw in the optional imptcp module. A crafted input sequence during
| oversize-frame recovery can cause an invalid internal message length
| and terminate rsyslogd. No confidentiality or integrity impact,
| privilege escalation, or code execution has been identified. imtcp
| and the default imptcp framing modes are not affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-19654
    https://www.cve.org/CVERecord?id=CVE-2026-19654
[1] https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
[2] https://github.com/rsyslog/rsyslog/pull/7410
[3] https://www.openwall.com/lists/oss-security/2026/07/22/5

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: rsyslog
Source-Version: 8.2504.0-1+deb13u1
Done: Michael Biebl <[email protected]>

We believe that the bug you reported is fixed in the latest version of
rsyslog, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Michael Biebl <[email protected]> (supplier of updated rsyslog package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Mon, 24 Aug 2026 15:56:02 +0200
Source: rsyslog
Architecture: source
Version: 8.2504.0-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Michael Biebl <[email protected]>
Changed-By: Michael Biebl <[email protected]>
Closes: 1141981 1144616
Changes:
 rsyslog (8.2504.0-1+deb13u1) trixie; urgency=medium
 .
   * omfwd regression fix: avoid false active target change log message.
     Patch backported from upstream Git. (Closes: #1141981)
   * imptcp: reject invalid regex-framing recovery transitions.
     (CVE-2026-19654, Closes: #1144616)
Checksums-Sha1:
 8deaf36214015a4ebff6293e8d0007698afb25f7 3452 rsyslog_8.2504.0-1+deb13u1.dsc
 7e4ddc551dbd97662d7a6184be3a36ed4aaa0f40 34268 
rsyslog_8.2504.0-1+deb13u1.debian.tar.xz
 9660a843ee4ab8e960c3a0dd95a1bed67313e46d 7905 
rsyslog_8.2504.0-1+deb13u1_source.buildinfo
Checksums-Sha256:
 5467bfa9e4ac35ddd746ea2e5ee9ad466473026f3e6c1129d35e88ccca277a78 3452 
rsyslog_8.2504.0-1+deb13u1.dsc
 f16d88d41ca75707aa2d99704d019bbaece865239d720b3c99bfe93dd0e79661 34268 
rsyslog_8.2504.0-1+deb13u1.debian.tar.xz
 10566e6fc4d61bc62db673e715f5eeb98387871eba8c61f71f557e13dc086bfb 7905 
rsyslog_8.2504.0-1+deb13u1_source.buildinfo
Files:
 92d46699b776bdeebecc9a863d6ccbd5 3452 admin optional 
rsyslog_8.2504.0-1+deb13u1.dsc
 078389082ee4311e256896acd190962a 34268 admin optional 
rsyslog_8.2504.0-1+deb13u1.debian.tar.xz
 7139850a4ea78f08e3cbac47ba708d77 7905 admin optional 
rsyslog_8.2504.0-1+deb13u1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEECbOsLssWnJBDRcxUauHfDWCPItwFAmqMTh8ACgkQauHfDWCP
Itw5yBAAgS7baRrBaqoHW38NqGr3urrJn0BN9Nj0vbgPU9xWRdt1OWnDpGsKMhY6
6IrfDlvlCijxZL+jBoMw9DZzU3FE/E7oAxeLa3OdHYGt66LTUab318oAS3gGDebn
45YBW/ZkFQzbrVN9soRCdECyuCxJdJ4gdGtmbsnXX+loqFK+AHapROPtZb/lZger
F46htMYuLQmKnrVACgna0hm/lcVQJbNyAQ4f31+dtQe7wZn5UmBU9JH+dizGn6Hq
SoUn1mWaRX179C4UnnAEzwBylQ+m+z5VLYcRvSHR2286EsQrkLDei1sG5HvntwSk
FG1hLY2PJR6ZF1Kj8efcPDlCcYVOpOU4RabpOHiVFJb6jCyDM5b6FJrayY5sJhTA
A/NBA71Bd0kLeFmsSDaP4a7YeuCJN2CXOCYBqMYoMx4hJimlqX67ezX0HA2qyDE6
7NHnfwDEmG1YajHY+KFoatMN+bFUgySDH1Z0lbi624I7g4jiVVA8TnFDhJUgz9Zj
NUtSphDmT1I0EPuCZB3BS75QLiR6Z1Y3EQAZ9TbZ6a2WkbvYnVHTDEyO5XTTdmH9
1PcYmtqv++BFVzFW1JZ2vCCeYV7xySOFlt51IvhI8vKWTADYzg2+zjBWAcGBU6nn
7Nt+JW+yUFpL3+wNbLsBYE8ui9LYoj8KGNjZk/A0THjgVoDEGgY=
=RcY4
-----END PGP SIGNATURE-----

Attachment: pgpxdPeKLw5E5.pgp
Description: PGP signature


--- End Message ---

Reply via email to