CVE-2019-17040: Rsyslog

Critical severity, CVSS 9.8. EPSS: 2.4% chance of exploitation in the next 30 days.

contrib/pmdb2diag/pmdb2diag.c in Rsyslog v8.1908.0 allows out-of-bounds access because the level length is mishandled.

Affected products

  • Rsyslog Rsyslog: version 8.1908.0 only

Published 2019-09-30. Last modified 2026-06-17.