RHSA-2022:4803: Important: rsyslog security update
The rsyslog packages provide an enhanced, multi-threaded syslog daemon. It supports MySQL, syslog/TCP, RFC 3195, permitted sender lists, filtering on any message part, and fine-grained control over output format.<br>Security Fix(es):<br><li> rsyslog: Heap-based overflow in TCP syslog server (CVE-2022-24903)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:4803?
The vulnerability RHSA-2022:4803 is classified as a Critical severity flaw.
How do I fix RHSA-2022:4803?
To fix RHSA-2022:4803, update the rsyslog packages to version 8.24.0-57.el7_9.3 or later.
What are the potential impacts of RHSA-2022:4803?
Exploitation of RHSA-2022:4803 can lead to a heap-based overflow, potentially allowing remote malicious code execution.
Which rsyslog packages are affected by RHSA-2022:4803?
Affected rsyslog packages include rsyslog, rsyslog-crypto, and rsyslog-mysql among others, prior to version 8.24.0-57.el7_9.3.
Is there a workaround for RHSA-2022:4803?
Currently, the recommended solution for RHSA-2022:4803 is to upgrade the affected packages, and no official workaround has been provided.