The rsyslog project disclosed a remote denial-of-service flaw in the optional imptcp input module that can let an unauthenticated attacker crash rsyslogd by sending a crafted input sequence during oversize-frame recovery when regex-based framing is enabled. The bug affects rsyslog versions v8.36.0 through v8.2606.0 and daily stable builds published before 2026-07-23 CEST, but only in deployments that explicitly enable imptcp with the non-default framing.delimiter.regex mode; default installations, imtcp, and default imptcp framing modes are not affected. Upstream said the fix would be included in stable release v8.2608.0 after publishing a proposed patch in GitHub PR #7410.
Ubuntu later issued USN-8598-1 to patch multiple rsyslog denial-of-service vulnerabilities in Ubuntu 26.04 LTS, 24.04 LTS, and 22.04 LTS. In addition to the regex-framing imptcp issue, Canonical said rsyslog also improperly handled oversized RFC5424 structured data in the mmpstrucdata module, allowing remote crashes; the notice explicitly identified that second flaw as CVE-2026-61548. Canonical published updated package versions for affected releases and advised users that a standard system update will install the fixes.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Ubuntu published USN-8598-1 to address multiple rsyslog vulnerabilities affecting Ubuntu 26.04 LTS, 24.04 LTS, and 22.04 LTS. The notice included fixed package versions and said the imptcp regex-framing issue could let a remote attacker crash rsyslog and cause a denial of service.
The rsyslog project disclosed a configuration-dependent remote denial-of-service flaw in the optional imptcp input module affecting regex-based framing. The issue affects rsyslog versions v8.36.0 through v8.2606.0, with a proposed upstream fix published in GitHub PR #7410 and a CVE still pending at the time of the advisory.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.