Executive brief
Rsyslog is a widely-deployed system for collecting and processing log messages across networks. The optional mmpstrucdata plugin, which parses RFC5424 structured log data, contains a stack buffer overflow flaw that allows an unauthenticated attacker to crash the logging service by sending a maliciously crafted log message. While code execution has not been demonstrated, attackers could disrupt critical log collection infrastructure in affected deployments.
Technical details
The mmpstrucdata plugin uses a fixed 32 KiB stack buffer (pVal[32 * 1024]) to store RFC5424 parameter values and calls parsePARAM_VALUE without bounds checking, allowing an attacker to overflow this buffer with a crafted parameter value larger than the buffer when the global MaxMessageSize permits it. The vulnerability requires that the mmpstrucdata plugin be installed and actively used in an action configuration, and that message-size limits are set high enough to allow the oversized parameter. The fix, released in version 8.2606.0, dynamically allocates buffers based on actual structured-data length rather than using a fixed-size stack buffer.
Affected products
- Rsyslog Project Rsyslog 7.5.4 through 8.2605.x
Timeline
- 2026-09-18: disclosed