Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-19654
Red Hat Red Hat Enterprise Linux 10 — Rsyslog: a configuration-dependent issue in rsyslog's optional imptcp input module can allow an unauthenticated remote peer to crash rsyslogd
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N H 7.5 .0047 38.1 —
AFFECTED
Product Versions Fixed
Red Hat Enterprise Linux 10 unspecified 0:8.2510.0-5.el10_2.1
Red Hat Enterprise Linux 10.0 Extended Update Support unspecified 0:8.2412.0-1.el10_0.1
Red Hat Enterprise Linux 9 unspecified 0:8.2510.0-2.el9_8.1
Red Hat Update Infrastructure 5 unspecified 1790241900
Red Hat Enterprise Linux 6 unspecified —
Red Hat Enterprise Linux 6 unspecified —
Red Hat Enterprise Linux 7 unspecified —
Red Hat Enterprise Linux 8 unspecified —
TIMELINE
Aug 12 Reserved by redhat
Aug 12 Published (CNA: redhat)
Sep 10 PATCH SHIPPED — CVE-2026-19654 (Red Hat Enterprise Linux 10.0 Extended Update Support). Fixed in Red Hat Enterprise Linux 10.0 Extended Update Support 0:8.2412.0-1.el10_0.1.
Description
A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame recovery can cause an invalid internal message length and terminate rsyslogd. No confidentiality or integrity impact, privilege escalation, or code execution has been identified. imtcp and the default imptcp framing modes are not affected.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| August 12, 2026 | Reserved | Reserved by redhat |
| August 12, 2026 | Published | Published (CNA: redhat) |
| September 10, 2026 | PATCH SHIPPED | PATCH SHIPPED — CVE-2026-19654 (Red Hat Enterprise Linux 10.0 Extended Update Support). Fixed in Red Hat Enterprise Linux 10.0 Extended Update Support 0:8.2412.0-1.el10_0.1. |
Affected
Affected products and packages — 8 rows
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Red Hat | Red Hat Enterprise Linux 10 | — | — | 0:8.2510.0-5.el10_2.1 |
| Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | — | — | 0:8.2412.0-1.el10_0.1 |
| Red Hat | Red Hat Enterprise Linux 9 | — | — | 0:8.2510.0-2.el9_8.1 |
| Red Hat | Red Hat Update Infrastructure 5 | — | — | 1790241900 |
| Red Hat | Red Hat Enterprise Linux 6 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 6 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 7 | — | — | — |
| Red Hat | Red Hat Enterprise Linux 8 | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-19654 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.