https://seclists.org/oss-sec/2026/q3/529: rsyslog: omfile dynaFile containment hardening (GHSA-xmp9-244p-5ggv)

Published Aug 20, 2026
·
Updated

Affected Software

1 affected component
rsyslog omfile output module (dynaFile)

Frequently Asked Questions

1

Which deployments need to assess this most closely?

Assess rsyslog configurations that use the omfile module with dynaFile, particularly where dynamic values can influence output paths. Deployments that intentionally allow paths outside a single static base directory are the relevant compatibility-sensitive cases.

2

Does the hardening constrain dynamic paths by default?

Where rsyslog can determine a static base path, the hardening adds default lexical containment. Earlier flexible behavior remained the default to avoid breaking existing logging configurations and did not provide a clear warning about path-containment risk.

3

What if an existing configuration intentionally requires paths to escape the base directory?

The hardening provides an explicit per-action compatibility opt-in for configurations that intentionally require path escape. This preserves the needed flexible behavior without making it the implicit default for applicable actions.

4

What can be done to reduce risk when unrestricted dynamic paths are not required?

Use the documented secure configuration mechanisms to constrain dynamic output paths. Those mechanisms were already the recommended approach for dynaFile configurations.

5

How can administrators identify configurations needing review?

Review omfile actions that use dynaFile and determine whether their generated filenames must remain under a static base path or intentionally escape it. The current hardening also adds diagnostics for the relevant dynamic-filename handling.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203