September 2026 rsyslog Vulnerabilities in StarWind Products
Title: September 2026 rsyslog Vulnerabilities in StarWind Products
Note: StarWind will continue to update this vulnerability as new information becomes available.
Vulnerability ID: SW-20260921-0002
Version: 1.0
Date: 2026-09-21
Status: Interim
CVEs: CVE-2026-19654, CVE-2026-61548, CVE-2026-78002
- Overview
- Affected Products
- Remediation
- Revision History
Summary
It was discovered that rsyslog incorrectly handled certain crafted inputs in three of its optional, non-default components. CVE-2026-19654 affects the optional imptcp input module during oversize-frame recovery. CVE-2026-61548 is a stack-based buffer overflow in the optional mmpstrucdata module while parsing RFC 5424 structured-data parameters. CVE-2026-78002 is a heap buffer overflow in the RainerScript replace() function (and the three-argument form of wrap()) when applied to sender-controlled data.
Impact
An unauthenticated remote peer could use CVE-2026-19654 or CVE-2026-78002 to crash the rsyslogd process, resulting in a denial of service for log collection. No confidentiality or integrity impact, privilege escalation, or code execution has been demonstrated for either issue. CVE-2026-61548 could allow memory corruption via a crafted structured-data parameter. All three issues require a non-default rsyslog configuration to be reachable: CVE-2026-19654 does not affect the default imptcp framing mode or imtcp; CVE-2026-61548 requires the mmpstrucdata module to be explicitly loaded; CVE-2026-78002 requires a ruleset that explicitly applies replace() or the three-argument wrap() to untrusted data.
Vulnerability Scoring
| CVE | CVSS 3.x Score | Vector | CVSS 4.0 Score | Vector |
|---|---|---|---|---|
| CVE-2026-19654 | 7.5 High | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | N/A | N/A |
| CVE-2026-61548 | 8.1 High | CVSS:3.1 (full vector not independently confirmed in this pass) | N/A | N/A |
| CVE-2026-78002 | 7.5 High | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H | N/A | N/A |
References
| Resource | Hyperlink |
|---|---|
| oss-security – CVE-2026-19654 / imptcp | https://osv.dev/vulnerability/CVE-2026-19654 |
| oss-security – CVE-2026-61548 / mmpstrucdata | https://seclists.org/oss-sec/2026/q3/173 |
| oss-security – CVE-2026-78002 / RainerScript replace() | https://openwall.com/lists/oss-security/2026/08/29/1 |
| Debian Security Tracker – rsyslog | https://security-tracker.debian.org/tracker/source-package/rsyslog |
| NIST NVD – CVE-2026-19654 | https://nvd.nist.gov/vuln/detail/CVE-2026-19654 |
| NIST NVD – CVE-2026-61548 | https://nvd.nist.gov/vuln/detail/CVE-2026-61548 |
| NIST NVD – CVE-2026-78002 | https://nvd.nist.gov/vuln/detail/CVE-2026-78002 |
Affected Products:
StarWind VSAN CVM Version 20260918 Version V8 (build 20104)
Software Versions and Fixes
None
Workaround
Until an update is available, exposure can be reduced by confirming the affected optional modules and ruleset functions are not enabled in the deployed rsyslog configuration: avoid non-default imptcp framing modes (CVE-2026-19654), do not load the mmpstrucdata module (CVE-2026-61548), and avoid applying replace() or the three-argument wrap() to sender-controlled data in RainerScript rulesets (CVE-2026-78002).
This section will be updated as patches are released
Obtaining Software Fixes
Software updates will be available in StarWind release notes – https://www.starwindsoftware.com/release-notes-build. To update the software, perform the steps described at the following link – https://knowledgebase.starwindsoftware.com/guidance/upgrading-from-any-starwind-version-to-any-starwind-version/ or contact support to perform an update. You can submit a support request using the following link https://www.starwindsoftware.com/support-form or contact Support directly via email support@starwind.com or via phone +1 617 829 4499.
Status of Notice
Interim
StarWind will continue to update information regarding this vulnerability as new details become available. This vulnerability article should be considered as the single source of current, up-to-date, authorized and accurate information posted by StarWind Software.
Revision History
| Revision # | Date | Comments |
|---|---|---|
| 1.0 | 2026-09-21 | Initial Public Release |