A configuration-dependent denial-of-service vulnerability in rsyslog's optional imptcp input module allows an unauthenticated remote peer to crash rsyslogd. The vulnerability exists in the non-default framing.delimiter.regex mode and can be triggered by a crafted input sequence during oversize-frame recovery, causing an invalid internal message length that terminates the rsyslogd daemon. No code execution, privilege escalation, or confidentiality/integrity impacts have been identified.
| Vendor | Product | Versions |
|---|---|---|
| rsyslog | rsyslog | 8.36.0 through 8.2606.0 |