CVE-2026-92709
Public on 2026-09-24
Modified on 2026-09-24
Description
rsyslog's omfile dynaFile facility intentionally allows templates to generate flexible output paths. This supports valid deployments that route logs into different directories or use dynamically generated file names.
A deployment becomes unsafe when a dynaFile template uses a value influenced by untrusted input as a path component without explicit secure-path handling. In that configuration, the rendered path can escape the operator's intended log directory.
This is not limited to the RFC5424 HOSTNAME field. Any untrusted value that reaches a dynaFile path component can create the condition.
An attacker who can influence such a value may cause rsyslog to create or append to files outside the intended output directory, subject to rsyslog's effective privileges and host confinement.
The practical result depends on the deployment. Mandatory access controls, systemd sandboxing, filesystem permissions, the configured input modules, and the selected output template can all limit or prevent impact. A code-execution outcome requires additional, deployment-specific conditions and is not representative of default distribution configurations.
Default Debian and Ubuntu configurations do not enable a network input and a dynaFile action of this form. The affected configuration must be explicitly deployed.
A deployment becomes unsafe when a dynaFile template uses a value influenced by untrusted input as a path component without explicit secure-path handling. In that configuration, the rendered path can escape the operator's intended log directory.
This is not limited to the RFC5424 HOSTNAME field. Any untrusted value that reaches a dynaFile path component can create the condition.
An attacker who can influence such a value may cause rsyslog to create or append to files outside the intended output directory, subject to rsyslog's effective privileges and host confinement.
The practical result depends on the deployment. Mandatory access controls, systemd sandboxing, filesystem permissions, the configured input modules, and the selected output template can all limit or prevent impact. A code-execution outcome requires additional, deployment-specific conditions and is not representative of default distribution configurations.
Default Debian and Ubuntu configurations do not enable a network input and a dynaFile action of this form. The affected configuration must be explicitly deployed.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | rsyslog | Pending Fix | ||
| Amazon Linux 2023 | rsyslog | Pending Fix | ||
| Amazon Linux 2027 Preview | rsyslog | Pending Fix |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 8.1 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |