CVE-2026-61548: Rsyslog: mmpstrucdata stack buffer overflow with oversized RFC5424 structured data
Last updated 20 July 2026
Other sources
Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseSDPARAM function in plugins/mmpstrucdata/mmpstrucdata.c stores RFC5424 parameter values in a fixed pVal[32 1024] stack buffer and calls parsePARAMVALUE without supplying the destination size. A remote unauthenticated attacker whose crafted RFC5424 message reaches an action using mmpstrucdata can provide a structured-data parameter larger than that buffer when MaxMessageSize permits it, causing an attacker-controlled stack overwrite. Deployments that do not install and use the plugin, or whose effective message-size limit remains below the required threshold, are not affected by this issue. The demonstrated impact is a crash and interruption of log collection; code execution is not demonstrated. This issue is fixed in version 8.2606.0.
— NVD
Rsyslog: mmpstrucdata stack buffer overflow with oversized RFC5424 structured data
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/rsyslogto a version that resolves this vulnerability.Fixed in 8.2606.0-4 - Upgrade
Upgrade
rsyslog (mmpstrucdata plugin)to a version that resolves this vulnerability.Fixed in 8.2606.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-61548?
CVE-2026-61548 has a risk score of 60, indicating a moderate severity level.
How do I fix CVE-2026-61548?
To mitigate CVE-2026-61548, update to the latest version of rsyslog that addresses this stack overflow issue.
What software is affected by CVE-2026-61548?
CVE-2026-61548 affects the rsyslog software, specifically distributions using Debian/rsyslog.
What does CVE-2026-61548 describe?
CVE-2026-61548 describes a stack overflow vulnerability in rsyslog's mmpstrucdata component.
When was CVE-2026-61548 published?
CVE-2026-61548 was published on July 20, 2026.