RHSA-2022:4799: Important: rsyslog security update
The rsyslog packages provide an enhanced, multi-threaded syslog daemon. It supports MySQL, syslog/TCP, RFC 3195, permitted sender lists, filtering on any message part, and fine-grained control over output format.Security Fix(es): rsyslog: Heap-based overflow in TCP syslog server (CVE-2022-24903) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rsyslogto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-cryptoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-crypto-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-debugsourceto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-docto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-elasticsearchto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-elasticsearch-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-gnutlsto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-gnutls-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-gssapito a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-gssapi-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-kafkato a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-kafka-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmauditto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmaudit-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmfieldsto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmfields-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmjsonparseto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmjsonparse-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmkubernetesto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmkubernetes-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmnormalizeto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmnormalize-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmsnmptrapdto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mmsnmptrapd-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mysqlto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-mysql-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-omamqp1to a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-omamqp1-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-opensslto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-openssl-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-pgsqlto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-relpto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-relp-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-snmpto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-udpspoofto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslog-udpspoof-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1 - Upgrade
Upgrade
redhat/rsyslogto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-cryptoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-crypto-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-debugsourceto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-elasticsearchto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-elasticsearch-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-gnutlsto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-gnutls-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-gssapito a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-gssapi-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-kafkato a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-kafka-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmauditto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmaudit-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmfieldsto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmfields-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmjsonparseto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmjsonparse-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmkubernetesto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmkubernetes-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmnormalizeto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmnormalize-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmsnmptrapdto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mmsnmptrapd-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mysqlto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-mysql-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-omamqp1to a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-omamqp1-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-opensslto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-openssl-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-pgsqlto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-pgsql-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-relpto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-relp-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-snmpto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-snmp-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-udpspoofto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Upgrade
Upgrade
redhat/rsyslog-udpspoof-debuginfoto a version that resolves this vulnerability.Fixed in 8.2102.0-7.el8_6.1.aa - Compensating control
Apply the rsyslog security update that fixes the heap-based overflow in the TCP syslog server (CVE-2022-24903).
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:4799?
The severity of RHSA-2022:4799 is classified as important due to a heap-based overflow in the TCP syslog function.
How do I fix RHSA-2022:4799?
To fix RHSA-2022:4799, you need to update the rsyslog package to version 8.2102.0-7.el8_6.1 or later.
Which systems are affected by RHSA-2022:4799?
RHSA-2022:4799 affects the rsyslog packages on Red Hat Enterprise Linux 8 systems.
What is the nature of the vulnerability in RHSA-2022:4799?
The vulnerability in RHSA-2022:4799 involves a heap-based overflow that could allow for remote code execution under certain conditions.
When was RHSA-2022:4799 released by Red Hat?
RHSA-2022:4799 was released by Red Hat on November 11, 2022.