{"id":"USN-5404-1","summary":"rsyslog vulnerability","details":"Pieter Agten discovered that Rsyslog incorrectly handled certain requests.\nAn attacker could possibly use this issue to cause a crash.\n","modified":"2026-04-27T16:05:22.271107Z","published":"2022-05-05T18:27:25Z","related":["UBUNTU-CVE-2022-24903"],"upstream":["CVE-2022-24903","UBUNTU-CVE-2022-24903"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5404-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-24903"}],"affected":[{"package":{"name":"rsyslog","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/rsyslog@8.32.0-1ubuntu4.2?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.32.0-1ubuntu4.2"}]}],"versions":["8.16.0-1ubuntu9","8.16.0-1ubuntu10","8.32.0-1ubuntu3","8.32.0-1ubuntu4"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"rsyslog","binary_version":"8.32.0-1ubuntu4.2"},{"binary_name":"rsyslog-czmq","binary_version":"8.32.0-1ubuntu4.2"},{"binary_name":"rsyslog-elasticsearch","binary_version":"8.32.0-1ubuntu4.2"},{"binary_version":"8.32.0-1ubuntu4.2","binary_name":"rsyslog-gnutls"},{"binary_name":"rsyslog-gssapi","binary_version":"8.32.0-1ubuntu4.2"},{"binary_name":"rsyslog-hiredis","binary_version":"8.32.0-1ubuntu4.2"},{"binary_version":"8.32.0-1ubuntu4.2","binary_name":"rsyslog-kafka"},{"binary_version":"8.32.0-1ubuntu4.2","binary_name":"rsyslog-mongodb"},{"binary_version":"8.32.0-1ubuntu4.2","binary_name":"rsyslog-mysql"},{"binary_name":"rsyslog-pgsql","binary_version":"8.32.0-1ubuntu4.2"},{"binary_name":"rsyslog-relp","binary_version":"8.32.0-1ubuntu4.2"}]},"database_specific":{"cves_map":{"cves":[{"id":"CVE-2022-24903","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:18.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5404-1.json"}},{"package":{"name":"rsyslog","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/rsyslog@8.2001.0-1ubuntu1.3?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.2001.0-1ubuntu1.3"}]}],"versions":["8.1901.0-1ubuntu4","8.2001.0-1ubuntu1","8.2001.0-1ubuntu1.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"rsyslog","binary_version":"8.2001.0-1ubuntu1.3"},{"binary_name":"rsyslog-czmq","binary_version":"8.2001.0-1ubuntu1.3"},{"binary_name":"rsyslog-elasticsearch","binary_version":"8.2001.0-1ubuntu1.3"},{"binary_name":"rsyslog-gnutls","binary_version":"8.2001.0-1ubuntu1.3"},{"binary_name":"rsyslog-gssapi","binary_version":"8.2001.0-1ubuntu1.3"},{"binary_name":"rsyslog-hiredis","binary_version":"8.2001.0-1ubuntu1.3"},{"binary_version":"8.2001.0-1ubuntu1.3","binary_name":"rsyslog-kafka"},{"binary_name":"rsyslog-mongodb","binary_version":"8.2001.0-1ubuntu1.3"},{"binary_name":"rsyslog-mysql","binary_version":"8.2001.0-1ubuntu1.3"},{"binary_name":"rsyslog-openssl","binary_version":"8.2001.0-1ubuntu1.3"},{"binary_name":"rsyslog-pgsql","binary_version":"8.2001.0-1ubuntu1.3"},{"binary_version":"8.2001.0-1ubuntu1.3","binary_name":"rsyslog-relp"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:20.04:LTS","cves":[{"id":"CVE-2022-24903","severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5404-1.json"}},{"package":{"name":"rsyslog","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/rsyslog@8.2112.0-2ubuntu2.2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8.2112.0-2ubuntu2.2"}]}],"versions":["8.2102.0-2ubuntu2","8.2110.0-3ubuntu1","8.2110.0-3ubuntu2","8.2110.0-4ubuntu1","8.2112.0-2ubuntu2"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"rsyslog","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_name":"rsyslog-czmq","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_name":"rsyslog-elasticsearch","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_name":"rsyslog-gnutls","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_name":"rsyslog-gssapi","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_version":"8.2112.0-2ubuntu2.2","binary_name":"rsyslog-hiredis"},{"binary_name":"rsyslog-kafka","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_name":"rsyslog-kubernetes","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_version":"8.2112.0-2ubuntu2.2","binary_name":"rsyslog-mongodb"},{"binary_name":"rsyslog-mysql","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_name":"rsyslog-openssl","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_name":"rsyslog-pgsql","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_name":"rsyslog-relp","binary_version":"8.2112.0-2ubuntu2.2"},{"binary_name":"rsyslog-snmp","binary_version":"8.2112.0-2ubuntu2.2"}]},"database_specific":{"cves_map":{"cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2022-24903"}],"ecosystem":"Ubuntu:22.04:LTS"},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5404-1.json"}}],"schema_version":"1.7.5"}