ELA-832-1 syslog-ng security update

Denial of service

2023-04-16
Packagesyslog-ng
Version3.5.6-2+deb8u1 (jessie), 3.8.1-10+deb9u1 (stretch)
Related CVEs CVE-2022-38725


It was discovered that an integer overflow in the RFC3164 parser of syslog-ng, a system logging daemon, may result in denial of service via malformed syslog messages.



For Debian 8 jessie, these problems have been fixed in version 3.5.6-2+deb8u1.

For Debian 9 stretch, these problems have been fixed in version 3.8.1-10+deb9u1.

We recommend that you upgrade your syslog-ng packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.