Related Vulnerabilities: CVE-2022-24903  

A flaw was found in rsyslog's reception TCP modules. This flaw allows an attacker to craft a malicious message leading to a heap-based buffer overflow. This issue allows the attacker to corrupt or access data stored in memory, leading to a denial of service in the rsyslog or possible remote code execution.

Description

A flaw was found in rsyslog's reception TCP modules. This flaw allows an attacker to craft a malicious message leading to a heap-based buffer overflow. This issue allows the attacker to corrupt or access data stored in memory, leading to a denial of service in the rsyslog or possible remote code execution.

Additional Information

  • Bugzilla 2081353: CVE-2022-24903 rsyslog: Heap-based overflow in TCP syslog server
  • CWE-787: Out-of-bounds Write
  • FAQ: Frequently asked questions about CVE-2022-24903