Alerts This Week
Warning Icon 1 548
Alerts This Week
Warning Icon 1 548

Mageia 9 Log4cxx Critical Silent Log Event Loss Vuln 2026-0218

mageia
Calendar Grey June 17, 2026
Dist Mageia Esm H88
Critical security update for Mageia affecting log4cxx due to log event loss in XMLLayout caused by unescaped characters.
Security update

Summary

Description: CVE-2026-40023, Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters

References

- https://bugs.mageia.org/show_bug.cgi?id=35352

- https://www.openwall.com/lists/oss-security/2026/04/10/12

- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/A7IXK4LCNBBYY5YSNHODMPEG64MYK6VE/

- https://www.cve.org/CVERecord?id=CVE-2026-40023

Resolution

SRPMS

- 9/core/log4cxx-1.1.0-1.1.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 17 Jun 2026 
URL: https://advisories.mageia.org/MGASA-2026-0218.html
Type: security
CVE: CVE-2026-40023

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here