CVE-2026-93402

Public on 2026-09-24
Modified on 2026-09-24
Description
The optional imdtls input module does not enforce tls.permittedpeer after a successful DTLS handshake when configured with tls.authmode="name" or tls.authmode="fingerprint".

After the handshake succeeds, imdtls performs the additional permitted-peer identity check. If that check fails, the module logs a warning but leaves the DTLS session active. The session is subsequently read and received records are passed to the configured ruleset.

A remote peer whose certificate is accepted by the listener's configured CA, but whose name or fingerprint is not listed in tls.permittedpeer, can inject chosen syslog records into the configured input stream.

The issue is limited to integrity of that input stream. It does not provide access to stored logs, modification or deletion of existing records, confidentiality loss, memory corruption, or code execution.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
4.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core rsyslog Not Affected
Amazon Linux 2023 rsyslog Not Affected
Amazon Linux 2027 Preview rsyslog Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N