diff --git a/meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654-regression.patch b/meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654-regression.patch new file mode 100644 index 0000000000..afab77b172 --- /dev/null +++ b/meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654-regression.patch @@ -0,0 +1,56 @@ +From fd358cb6b9a773d6c4c223735745104c0deacc4f Mon Sep 17 00:00:00 2001 +From: Rainer Gerhards +Date: Mon, 20 Jul 2026 18:19:17 +0200 +Subject: [PATCH 2/2] tests: assert imptcp regex oversize diagnostics + +Why +The test called a nonexistent helper, so its diagnostic assertions did not run. + +Impact +The regression test now fails if oversize recovery diagnostics are missing. + +Before/After +Before: missing helper calls silently left the diagnostics unchecked. +After: supported regex assertions verify both expected diagnostics. + +Technical Overview +Use the testbench content_check helper with its regex option. +Document the oversize-recovery invariant and clean-shutdown oracle. +Keep the existing data stream and expected framed output unchanged. + +With the help of AI-Agents: Codex + +CVE: CVE-2026-19654 +Upstream-Status: Backport [https://github.com/rsyslog/rsyslog/commit/8e67ae69539153e4e80547dfb5f07ed17222e292] + +(cherry picked from commit 8e67ae69539153e4e80547dfb5f07ed17222e292) +Signed-off-by: Deepak Rathore +--- + tests/imptcp_framing_regex-oversize.sh | 7 +++++-- + 1 file changed, 5 insertions(+), 2 deletions(-) + +diff --git a/tests/imptcp_framing_regex-oversize.sh b/tests/imptcp_framing_regex-oversize.sh +index c5b74ddb1..67b63d8e7 100755 +--- a/tests/imptcp_framing_regex-oversize.sh ++++ b/tests/imptcp_framing_regex-oversize.sh +@@ -1,5 +1,8 @@ + #!/bin/bash + # This file is part of the rsyslog project, released under ASL 2.0 ++# Regression coverage for regex-framed imptcp oversize recovery. The configured ++# 256-byte limit forces the recovery path; clean shutdown plus the two internal ++# diagnostics prove that recovery completed without corrupting parser state. + . ${srcdir:=.}/diag.sh init + generate_conf + add_conf ' +@@ -40,6 +43,6 @@ NEWMSG: <33>Mar 1 01:00:00 172.20.245.8 tag multi + line3 + NEWMSG: <33>Mar 1 01:00:00 172.20.245.8 tag test4' + cmp_exact +-content_check-regex "assuming end of frame" ${RSYSLOG2_OUT_LOG} +-content_check-regex "message too long" ${RSYSLOG2_OUT_LOG} ++content_check --regex "assuming end of frame" "${RSYSLOG2_OUT_LOG}" ++content_check --regex "message too long" "${RSYSLOG2_OUT_LOG}" + exit_test +-- +2.53.0 + diff --git a/meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654.patch b/meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654.patch new file mode 100644 index 0000000000..1e6b390646 --- /dev/null +++ b/meta-oe/recipes-extended/rsyslog/rsyslog/CVE-2026-19654.patch @@ -0,0 +1,51 @@ +From a680861018de25b2fb2e83d64c725ddbbb91a7db Mon Sep 17 00:00:00 2001 +From: Rainer Gerhards +Date: Mon, 20 Jul 2026 17:19:28 +0200 +Subject: [PATCH 1/2] imptcp: guard regex framing match at line start + +Why +A regex match at the beginning of the receive buffer can form a +negative message length after oversize-frame recovery. + +Impact +Regex-framed imptcp listeners reject that invalid transition instead +of submitting a negative message length. + +Before/After +Before: a match with a zero line offset submitted an invalid length. +After: only a match following an existing line can submit a frame. + +Technical Overview +Mirror the line-offset guard used by the shared imtcp parser. +Leave existing regex framing and oversize recovery behavior unchanged. + +Security advisory: +https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29 + +Reported-by: Raphael Eikenberg (@eikendev) +With the help of AI-Agents: Codex + +CVE: CVE-2026-19654 +Upstream-Status: Backport [https://github.com/rsyslog/rsyslog/commit/07b3c40a5a78c79ed9109251f842ca7e955dd586] + +(cherry picked from commit 07b3c40a5a78c79ed9109251f842ca7e955dd586) +Signed-off-by: Deepak Rathore +--- + plugins/imptcp/imptcp.c | 2 +- + 1 file changed, 1 insertion(+), 1 deletion(-) + +diff --git a/plugins/imptcp/imptcp.c b/plugins/imptcp/imptcp.c +index 363d8fa5a..8470e93eb 100644 +--- a/plugins/imptcp/imptcp.c ++++ b/plugins/imptcp/imptcp.c +@@ -1009,7 +1009,7 @@ static rsRetVal ATTR_NONNULL() processDataRcvd_regexFraming(ptcpsess_t *const __ + pThis->iCurrLine = pThis->iMsg; + } else { + const int isMatch = !regexec(&inst->start_preg, (char *)pThis->pMsg + pThis->iCurrLine, 0, NULL, 0); +- if (isMatch) { ++ if (pThis->iCurrLine > 0 && isMatch) { + DBGPRINTF("regex match (%d), framing line: %s\n", pThis->iCurrLine, pThis->pMsg); + strcpy((char *)pThis->pMsg_save, (char *)pThis->pMsg + pThis->iCurrLine); + pThis->iMsg = pThis->iCurrLine - 1; +-- +2.53.0 diff --git a/meta-oe/recipes-extended/rsyslog/rsyslog_8.2512.0.bb b/meta-oe/recipes-extended/rsyslog/rsyslog_8.2512.0.bb index 186e1ccf24..5ab4a65e67 100644 --- a/meta-oe/recipes-extended/rsyslog/rsyslog_8.2512.0.bb +++ b/meta-oe/recipes-extended/rsyslog/rsyslog_8.2512.0.bb @@ -25,6 +25,8 @@ SRC_URI = "https://www.rsyslog.com/files/download/rsyslog/${BPN}-${PV}.tar.gz \ file://run-ptest \ file://0001-tests-disable-the-check-for-inotify.patch \ file://0001-tests-tcpflood.c-Pass-correct-parameter-type-to-send.patch \ + file://CVE-2026-19654.patch \ + file://CVE-2026-19654-regression.patch \ " SRC_URI:append:libc-musl = " \