{"id":"CVE-2026-61548","summary":"Rsyslog: mmpstrucdata stack buffer overflow with oversized RFC5424 structured data","details":"Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSD_PARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 * 1024] stack buffer and calls parsePARAM_VALUE without supplying the destination size. A remote unauthenticated attacker whose crafted RFC5424 message reaches an action using mmpstrucdata can provide a structured-data parameter larger than that buffer when MaxMessageSize permits it, causing an attacker-controlled stack overwrite. Deployments that do not install and use the plugin, or whose effective message-size limit remains below the required threshold, are not affected by this issue. The demonstrated impact is a crash and interruption of log collection; code execution is not demonstrated. This issue is fixed in version 8.2606.0.","aliases":["GHSA-8qmr-c66f-g368"],"modified":"2026-10-06T08:28:32.092325888Z","published":"2026-09-18T16:54:28.925Z","related":["SUSE-SU-2026:23122-1","SUSE-SU-2026:23145-1","SUSE-SU-2026:3442-1","SUSE-SU-2026:3478-1","SUSE-SU-2026:3498-1","SUSE-SU-2026:3518-1","openSUSE-SU-2026:11407-1","openSUSE-SU-2026:21535-1"],"database_specific":{"cwe_ids":["CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61548.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2026/07/20/1"},{"type":"WEB","url":"https://github.com/rsyslog/rsyslog/releases/tag/v8.2606.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/61xxx/CVE-2026-61548.json"},{"type":"ADVISORY","url":"https://github.com/rsyslog/rsyslog/security/advisories/GHSA-8qmr-c66f-g368"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-61548"},{"type":"FIX","url":"https://github.com/rsyslog/rsyslog/commit/bcda60a3692efdf0c8e44102528f5a0ebe0dec6d"},{"type":"FIX","url":"https://github.com/rsyslog/rsyslog/pull/6991"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/rsyslog/rsyslog","events":[{"introduced":"9b104f782c0dd9440db27305cd87fd68414fce16"},{"fixed":"bcda60a3692efdf0c8e44102528f5a0ebe0dec6d"},{"fixed":"13d51f0c8da399a5778d52353d2b2f848fdd40e9"}],"database_specific":{"extracted_events":[{"introduced":"7.5.4"},{"fixed":"8.2606.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"database_specific":{"vanir_signatures":[{"target":{"file":"plugins/mmpstrucdata/mmpstrucdata.c"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["172302818378424559232349661186384991082","204576049524538653050159547573458860841","207218992799397692856582696679164764563","79968204490481608902335056599928331550","113138679155749592903749548948148863634","275517750128763342588176335086732884101","137858611727895455758232248843982981096","107266431909351735958275965781950733101","304685271771449870921572212047955210718","179759163390957868406256096131563507017","151092078056809062591676835097709693044","184153115516506506966906414809782946477","44502876360982216193597271014288917937","228934448672114445602990785025170321654","32866122144647260851277595088281701056","63652227113797548785778373156972002737","312813389180697676190273741761762609373","83188012311193936293508348762633787830","26353449849245447976868192381825061071","79805915872889760001567897671242228351","139980924155249253391598434888857438735","338016503734684191808758051212872194384","307712074453564265088575440744175182148","126729062470589388146711919301357785046","23336827436931619741695596269012628287","107044023656330495523405325398625207200","228380664743675936519741278092367001931","46388044587022862621643883151107739379","73878749272702880318043619538012628844","255603074538393362490350651521806191705","191981195498856826813973415254729900407","205698382219396130399261281569223172355","202497994053480507386922044528541587280","31995042920229616401674451824491400357","276216928398001781322231269310424040440","38789844334308956922038458371493682396","339219714947239825527844797897843580871","156854777301957510890358881443629499809","121701964295418687290651770236619285233","103294109116334698598984300916274178115","117335881231623644842032832996784689155","78157123261555539098175829214227996194","188712650336953620788564642877677925444","183279764951541759638084992116309086929","6905026506148364230493804294348630069","334141909019021606732047588244207273960","146664734798201370474317016835396488635","212872364255858646645498521799775238907","112964070874247620552356571226412368638","163856514964710834502338467390712591286","98106826226013823445964508332701850623","55575131052706875377345725123651747518","8607657687572624939534454113422064232","199786343429892544491347315294937741092","86298253700462546164746132084515838603","158629635037388056546904990810349476180","152528644150019770978567014372704638876","80731956808986757759722329103048498338","3481218161290293485344238674229595064","112159216586508247002106381125147134111","142122860169540710595854914867597866928","105364738126146413637146049354848569247","331732570542977995570584729827473653701","224692381096507683523326860248204085619","314348289580422055884976078952966313839","75495317777656003753613588794878943703","228217027841082320644131316079868695709","55575131052706875377345725123651747518","78543367120673322370084174114081336498","247789903645227586323884786505596113670","265683509364757050705572293075512839778","26144349258196012395901436847637237373","196367702372878751152768053265813410771","197553085396509583971444226375236246356","112773272372226752692016071287909788844","32820438530130871424448867618776803303","112181683862138298237981425764355103752","287432326814419594253961733520534454757","322767395125833890040335086284609528276","20563306664148125097477778797318612349"]},"id":"CVE-2026-61548-421efa7e","signature_type":"Line","signature_version":"v1","source":"https://github.com/rsyslog/rsyslog/commit/bcda60a3692efdf0c8e44102528f5a0ebe0dec6d"},{"deprecated":false,"digest":{"function_hash":"284571728972620097089859014222661595946","length":108},"id":"CVE-2026-61548-ae45c7ac","signature_type":"Function","signature_version":"v1","source":"https://github.com/rsyslog/rsyslog/commit/bcda60a3692efdf0c8e44102528f5a0ebe0dec6d","target":{"file":"plugins/mmpstrucdata/mmpstrucdata.c","function":"setInstParamDefaults"}},{"source":"https://github.com/rsyslog/rsyslog/commit/bcda60a3692efdf0c8e44102528f5a0ebe0dec6d","target":{"file":"runtime/msg.h"},"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["299505039592686159768272911745407844183","174384025944184512240266712415008600584","286433245372955779247848029624248014408","132239781654422181542953979769343300281"]},"id":"CVE-2026-61548-f207e251","signature_type":"Line","signature_version":"v1"}],"vanir_signatures_modified":"2026-10-06T08:28:32Z","source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-61548.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}