Heap-based buffer overflow in rsyslog - CVE-2022-24903
Published: May 5, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service or potentially execute arbitrary code on the target system.
The vulnerability exists due to a boundary error when parsing data in imtcp, imptcp, imgssapi, and imhttp modules used for TCP syslog reception. A remote attacker can pass specially crafted data to the application, trigger heap-based buffer overflow and cause a denial of service or potentially execute arbitrary code on the target system.
Successful exploitation of this vulnerability is possible if the attacker is able to directly send specially crafted messages to the rsyslog daemon or by injecting specially crafted data into log files. Vulnerability exploitation in the second scenario requires that the rsyslog client supports octet-counted framing, which is not a default configuration.
Affected software
Oracle VM Server for x86
Oracle Communications Diameter Signaling Router
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Session Smart Router
Amazon Linux AMI
Gentoo Linux
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - Extended Life Cycle Support
Red Hat Enterprise Linux Server - Extended Life Cycle Support (for IBM z Systems)
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for Power, big endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Anolis OS
HPE Helion Openstack
SUSE OpenStack Cloud
SUSE OpenStack Cloud Crowbar
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Oracle Linux
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Module for Server Applications
openSUSE Leap
Ubuntu
openEuler
Fedora
Cognos Dashboards on Cloud Pak for Data
EMC ECS
Watson Studio on Cloud Pak for Data
XtremIO X2
CloudLink
elfutils (Red Hat package)
imgbased (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
redhat-virtualization-host-productimg (Red Hat package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
ovirt-node-ng (Red Hat package)
rsyslog (Red Hat package)
rsyslog7 (Red Hat package)
rsyslog
rsyslog-debuginfo
rsyslog-debugsource
rsyslog-diag-tools
rsyslog-diag-tools-debuginfo
rsyslog-doc
rsyslog-module-gssapi
rsyslog-module-gssapi-debuginfo
rsyslog-module-gtls
rsyslog-module-gtls-debuginfo
rsyslog-module-mysql
rsyslog-module-mysql-debuginfo
rsyslog-module-pgsql
rsyslog-module-relp
rsyslog-module-relp-debuginfo
rsyslog-module-snmp
rsyslog-module-snmp-debuginfo
rsyslog-module-udpspoof
rsyslog-module-udpspoof-debuginfo
rsyslog-module-pgsql-debuginfo
rsyslog (Ubuntu package)
rsyslog-module-mmnormalize
rsyslog-module-mmnormalize-debuginfo
rsyslog-crypto
rsyslog-elasticsearch
rsyslog-gnutls
rsyslog-gssapi
rsyslog-kafka
rsyslog-libdbi
rsyslog-mmaudit
rsyslog-mmjsonparse
rsyslog-mmkubernetes
rsyslog-mmnormalize
rsyslog-mmsnmptrapd
rsyslog-mysql
rsyslog-pgsql
rsyslog-relp
rsyslog-snmp
rsyslog-udpspoof
rsyslog (Debian package)
rsyslog-hiredis
rsyslog-mongodb
rsyslog-omamqp1
rsyslog-rabbitmq
rsyslog-help
rsyslog-module-dbi
rsyslog-module-elasticsearch
rsyslog-module-ossl-debuginfo
rsyslog-module-ossl
rsyslog-module-omtcl-debuginfo
rsyslog-module-omtcl
rsyslog-module-omhttpfs-debuginfo
rsyslog-module-omhttpfs
rsyslog-module-omamqp1-debuginfo
rsyslog-module-omamqp1
rsyslog-module-dbi-debuginfo
rsyslog-module-elasticsearch-debuginfo
rsyslog-module-gcrypt
rsyslog-module-gcrypt-debuginfo
app-admin/rsyslog
Red Hat Virtualization
OpenShift Data Foundation (formerly OpenShift Container Storage)
Red Hat Virtualization Host
Red Hat Virtualization Manager
IBM Security Verify Access
IBM Security Guardium
RUGGEDCOM ROX MX5000RE
RUGGEDCOM ROX RX5000
RUGGEDCOM ROX RX1536
RUGGEDCOM ROX RX1524
RUGGEDCOM ROX RX1512
RUGGEDCOM ROX RX1511
RUGGEDCOM ROX RX1510
RUGGEDCOM ROX RX1501
RUGGEDCOM ROX RX1500
RUGGEDCOM ROX RX1400
RUGGEDCOM ROX MX5000
HPE Moonshot 1500 Chassis Manager
Red Hat OpenShift Container Platform
Dell EMC NetWorker vProxy
Dell EMC Storage Monitoring and Reporting (SMR)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Dell EMC Unity Operating Environment (OE)
Dell EMC VxRail Appliance
How to mitigate CVE-2022-24903
elfutils (Red Hat package) - update to 0.186-1.el8
imgbased (Red Hat package) - update to 1.2.24-1.el8ev
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.23-1.el7ev, 4.5.0-5.el8ev
redhat-virtualization-host (Red Hat package) - update to 4.3.23-20220622.0.el7_9
redhat-virtualization-host-productimg (Red Hat package) - addressed in versions 4.3.23-1.el7, 4.5.0-2.el8
IBM Security Verify Access - update to 10.0.5.0
RUGGEDCOM ROX MX5000RE - update to 2.16.0
RUGGEDCOM ROX RX5000 - update to 2.16.0
RUGGEDCOM ROX RX1536 - update to 2.16.0
RUGGEDCOM ROX RX1524 - update to 2.16.0
RUGGEDCOM ROX RX1512 - update to 2.16.0
RUGGEDCOM ROX RX1511 - update to 2.16.0
RUGGEDCOM ROX RX1510 - update to 2.16.0
RUGGEDCOM ROX RX1501 - update to 2.16.0
RUGGEDCOM ROX RX1500 - update to 2.16.0
RUGGEDCOM ROX RX1400 - update to 2.16.0
RUGGEDCOM ROX MX5000 - update to 2.16.0
EMC ECS - update to 3.8.0.2
HPE Moonshot 1500 Chassis Manager - update to 4.0-b43
Dell EMC NetWorker vProxy - update to 4.3.0-34
ovirt-node-ng (Red Hat package) - update to 4.4.2-1.el8ev
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 4.5.1
Dell EMC Storage Monitoring and Reporting (SMR) - update to 4.8.0.0
Watson Studio on Cloud Pak for Data - addressed in versions 4.8.7, 5.1.0
Red Hat OpenShift Container Platform - update to 4.11.0
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.13.0
Dell EMC Unity XT Operating Environment (OE) - update to 5.2.1.0.5.013
Dell EMC Unity VSA Operating Environment (OE) - update to 5.2.1.0.5.013
Dell EMC Unity Operating Environment (OE) - update to 5.2.1.0.5.013
Session Smart Router - addressed in versions 5.4.7, 5.5.3
rsyslog (Red Hat package) - addressed in versions 5.8.10-12.el6_10.1, 8.24.0-57.el7_9.3, 8.37.0-13.el8_1.1, 8.1911.0-3.el8_2.1, 8.1911.0-7.el8_4.3, 8.2102.0-7.el8_6.1, 8.2102.0-101.el9_0.1
XtremIO X2 - update to 6.4.2-13
Dell EMC VxRail Appliance - addressed in versions 7.0.372, 8.0.000
CloudLink - update to 7.1.4
rsyslog7 (Red Hat package) - update to 7.4.10-7.el6_10.1
rsyslog - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-debuginfo - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-debugsource - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-diag-tools - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-diag-tools-debuginfo - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-doc - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-gssapi - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-gssapi-debuginfo - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-gtls - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-gtls-debuginfo - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-mysql - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-mysql-debuginfo - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-pgsql - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-relp - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-relp-debuginfo - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-snmp - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-snmp-debuginfo - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-udpspoof - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-udpspoof-debuginfo - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-pgsql-debuginfo - addressed in versions 8.4.0-18.16.1, 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog (Ubuntu package) - addressed in versions 8.16.01ubuntu3.1+esm2, 8.32.0-1ubuntu4.2, 8.2001.0-1ubuntu1.3, 8.2102.0-2ubuntu2.2, 8.2112.0-2ubuntu2.2
rsyslog-module-mmnormalize - addressed in versions 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog-module-mmnormalize-debuginfo - addressed in versions 8.24.0-3.58.2, 8.33.1-150000.3.37.1, 8.2106.0-8.5.2, 8.2106.0-150200.4.26.1
rsyslog - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-crypto - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-elasticsearch - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-gnutls - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-gssapi - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-kafka - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-libdbi - update to 8.24.0-57.0.1
rsyslog-mmaudit - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-mmjsonparse - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-mmkubernetes - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-mmnormalize - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-mmsnmptrapd - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-mysql - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-pgsql - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-relp - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-snmp - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-udpspoof - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog-doc - addressed in versions 8.24.0-57.0.1, 8.2102.0-7
rsyslog (Debian package) - addressed in versions 8.1901.0-1+deb10u2, 8.2102.0-2+deb11u1
rsyslog - update to 8.2006.0-7
rsyslog-debuginfo - update to 8.2006.0-7
rsyslog-debugsource - update to 8.2006.0-7
rsyslog-hiredis - update to 8.2006.0-7
rsyslog-kafka - update to 8.2006.0-7
rsyslog-mmkubernetes - update to 8.2006.0-7
rsyslog-mmnormalize - update to 8.2006.0-7
rsyslog-mongodb - update to 8.2006.0-7
rsyslog-omamqp1 - update to 8.2006.0-7
rsyslog-pgsql - update to 8.2006.0-7
rsyslog-rabbitmq - update to 8.2006.0-7
rsyslog-relp - update to 8.2006.0-7
rsyslog-help - update to 8.2006.0-7
rsyslog-omamqp1 - update to 8.2102.0-7
rsyslog-module-dbi - update to 8.2106.0-150200.4.26.1
rsyslog-module-elasticsearch - update to 8.2106.0-150200.4.26.1
rsyslog-module-ossl-debuginfo - update to 8.2106.0-150200.4.26.1
rsyslog-module-ossl - update to 8.2106.0-150200.4.26.1
rsyslog-module-omtcl-debuginfo - update to 8.2106.0-150200.4.26.1
rsyslog-module-omtcl - update to 8.2106.0-150200.4.26.1
rsyslog-module-omhttpfs-debuginfo - update to 8.2106.0-150200.4.26.1
rsyslog-module-omhttpfs - update to 8.2106.0-150200.4.26.1
rsyslog-module-omamqp1-debuginfo - update to 8.2106.0-150200.4.26.1
rsyslog-module-omamqp1 - update to 8.2106.0-150200.4.26.1
rsyslog-module-dbi-debuginfo - update to 8.2106.0-150200.4.26.1
rsyslog-module-elasticsearch-debuginfo - update to 8.2106.0-150200.4.26.1
rsyslog-module-gcrypt - update to 8.2106.0-150200.4.26.1
rsyslog-module-gcrypt-debuginfo - update to 8.2106.0-150200.4.26.1
rsyslog - addressed in versions 8.2204.0-1.fc35, 8.2204.0-1.fc37
app-admin/rsyslog - update to 8.2206.0
External References
Related Security Bulletins
- Heap-based buffer overflow in rsyslog
- Ubuntu update for rsyslog
- Ubuntu update for rsyslog
- Debian update for rsyslog
- Red Hat Enterprise Linux 8.1 Update Services for SAP Solutions update for rsyslog
- Red Hat Enterprise Linux 8.4 Extended Update Support update for rsyslog
- Red Hat Enterprise Linux 8.2 Extended Update Support update for rsyslog
- Red Hat Enterprise Linux 8.6 update for rsyslog
- Red Hat Enterprise Linux 6 Extended Lifecycle Support update for rsyslog and rsyslog7
- Red Hat Enterprise Linux 7 update for rsyslog
- Red Hat Enterprise Linux 9 update for rsyslog
- Multiple vulnerabilities in Red Hat Virtualization 4 for RHEL 8
- Amazon Linux AMI update for rsyslog
- Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 update for redhat-release-virtualization-host and redhat-virtualization-host
- SUSE update for rsyslog
- SUSE update for rsyslog
- SUSE update for rsyslog
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Dell Unity, Dell UnityVSA, and Dell Unity XT
- Multiple vulnerabilities in Dell CloudLink
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in OpenShift Container Platform 4.11
- Multiple vulnerabilities in Dell NetWorker vProxy
- Multiple vulnerabilities in Dell VxRail
- Multiple vulnerabilities in Juniper Networks Session Smart Router
- Multiple vulnerabilities in Dell Storage Monitoring and Reporting (SMR)
- Multiple vulnerabilities in Dell VxRail Appliance components
- Multiple vulnerabilities in IBM Security Verify Access
- IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data update for rsyslog
- Multiple vulnerabilities in Oracle Communications Diameter Signaling Router
- SUSE update for rsyslog
- SUSE update for rsyslog
- Multiple vulnerabilities in Oracle VM Server for x86
- Multiple vulnerabilities in Dell ECS
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.13
- Multiple vulnerabilities in Siemens RUGGEDCOM ROX devices
- Multiple vulnerabilities in IBM Security Guardium
- openEuler update for rsyslog
- Multiple vulnerabilities in IBM Cognos Dashboards on Cloud Pak for Data
- Amazon Linux AMI update for rsyslog
- Gentoo update for rsyslog
- Multiple vulnerabilities in HPE Moonshot 1500 Chassis Manager
- Fedora 35 update for rsyslog
- Fedora 37 update for rsyslog
- Multiple vulnerabilities in Dell XtremIO X2
- Multiple vulnerabilities in IBM Watson Studio on Cloud Pak for Data
- Anolis OS update for rsyslog
- Anolis OS update for rsyslog