CVE-2018-16881: Debian Linux

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

A denial of service vulnerability was found in rsyslog in the imptcp module. An attacker could send a specially crafted message to the imptcp socket, which would cause rsyslog to crash. Versions before 8.27.0 are vulnerable.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Red Hat Enterprise Linux Desktop: version 7.0 only
  • Red Hat Enterprise Linux For IBM Z Systems: version 7.0 only
  • Red Hat Enterprise Linux For Power Big Endian: version 7.0 only
  • Red Hat Enterprise Linux For Power Little Endian: version 7.0 only
  • Red Hat Enterprise Linux For Scientific Computing: version 7.0 only
  • Red Hat Enterprise Linux Server: version 7.0 only
  • Red Hat Enterprise Linux Workstation: version 7.0 only
  • Red Hat Virtualization: version 4.0 only
  • Red Hat Virtualization Host: version 4.0 only
  • Red Hat Virtualization Manager: version 4.3 only
  • Rsyslog Rsyslog: before 8.27.0 (fixed in 8.27.0)

Published 2019-01-25. Last modified 2026-06-17.