CVE-2026-93402
Public on 2026-09-24
Modified on 2026-09-24
Description
The optional imdtls input module does not enforce tls.permittedpeer after a successful DTLS handshake when configured with tls.authmode="name" or tls.authmode="fingerprint".
After the handshake succeeds, imdtls performs the additional permitted-peer identity check. If that check fails, the module logs a warning but leaves the DTLS session active. The session is subsequently read and received records are passed to the configured ruleset.
A remote peer whose certificate is accepted by the listener's configured CA, but whose name or fingerprint is not listed in tls.permittedpeer, can inject chosen syslog records into the configured input stream.
The issue is limited to integrity of that input stream. It does not provide access to stored logs, modification or deletion of existing records, confidentiality loss, memory corruption, or code execution.
After the handshake succeeds, imdtls performs the additional permitted-peer identity check. If that check fails, the module logs a warning but leaves the DTLS session active. The session is subsequently read and received records are passed to the configured ruleset.
A remote peer whose certificate is accepted by the listener's configured CA, but whose name or fingerprint is not listed in tls.permittedpeer, can inject chosen syslog records into the configured input stream.
The issue is limited to integrity of that input stream. It does not provide access to stored logs, modification or deletion of existing records, confidentiality loss, memory corruption, or code execution.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | rsyslog | Not Affected | ||
| Amazon Linux 2023 | rsyslog | Not Affected | ||
| Amazon Linux 2027 Preview | rsyslog | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 4.3 | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |