CVE-2026-78002: Red Hat Enterprise Linux 10

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A flaw was found in rsyslog. An unauthenticated remote attacker can trigger a heap buffer overflow in the RainerScript `replace()` function by sending specially crafted syslog messages. This vulnerability arises from an incorrect buffer size calculation during string replacement, causing memory corruption. Successful exploitation can lead to a denial of service (DoS) for the affected system.

Affected products

  • Red Hat Red Hat Enterprise Linux 10: before 0:8.2510.0-5.el10_2.2 (fixed in 0:8.2510.0-5.el10_2.2)
  • Red Hat Red Hat Enterprise Linux 6
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9: before 0:8.2510.0-2.el9_8.2 (fixed in 0:8.2510.0-2.el9_8.2)
  • Red Hat Red Hat Update Infrastructure 5: before 1790241900 (fixed in 1790241900)

Published 2026-08-27. Last modified 2026-09-25.