VDB
Sign up
MEDIUM6.5

GHSA-2mj3-6grc-px38

Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration

Quick fix

GHSA-2mj3-6grc-px38 — github.com/elastic/beats/v7: upgrade to the fixed version with the command below.

go get github.com/elastic/beats/v7@v8.19.9

Details

Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a malformed Syslog message or a malicious tokenizer pattern in the Dissect configuration.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/elastic/beats/v7
Introduced in: 7.7.0Fixed in: 8.19.9
Fixgo get github.com/elastic/beats/v7@v8.19.9
Go/github.com/elastic/beats/v7
Introduced in: 9.0.0Fixed in: 9.1.9
Fixgo get github.com/elastic/beats/v7@v9.1.9
Go/github.com/elastic/beats/v7
Introduced in: 9.2.0Fixed in: 9.2.3
Fixgo get github.com/elastic/beats/v7@v9.2.3
Go/github.com/elastic/beats/v7
Introduced in: 0Fixed in: 7.0.0-alpha2.0.20251204214633-dd3af18220bf
Fixgo get github.com/elastic/beats/v7@v7.0.0-alpha2.0.20251204214633-dd3af18220bf
Go/github.com/elastic/beats
Introduced in: 0

No fixed version published yet for github.com/elastic/beats (go modules). Pin to a known-safe version or switch to an alternative.

References