Stack-based buffer overflow in rsyslog - CVE-2026-93403
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a stack-based buffer overflow in the mmpstrucdata output module when parsing crafted RFC 5424 messages. A remote attacker can send a crafted RFC 5424 message containing an oversized structured-data parameter value to cause a denial of service.
Only configurations that load and use mmpstrucdata and permit sufficiently large messages are affected.