Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

SUSE 2026-1843-1 Log4j Moderate Vulnerability With Four Key Fixes

suse
Calendar Grey May 13, 2026
Dist Suse Esm H88
An update for log4j addresses multiple vulnerabilities. Crucial for maintaining system integrity and security.
An update that solves four vulnerabilities can now be installed.

Summary

## This update for log4j fixes the following issues: * CVE-2026-34477: TLS connections vulnerable to interception due to incomplete hostname verification configuration checks (bsc#1262050). * CVE-2026-34479: silent log event loss due to improper XML escaping in `Log4j1XmlLayout` (bsc#1262091). * CVE-2026-34480: silent log event loss due to improper XML escaping in `XmlLayout` (bsc#1262092). * CVE-2026-34481: silent log event loss due to improper serialization of non- finite floating-point values in `JsonTemplateLayout` (bsc#1262093). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7

References

* bsc#1262050

* bsc#1262091

* bsc#1262092

* bsc#1262093

Cross-

* CVE-2026-34477

* CVE-2026-34479

* CVE-2026-34480

* CVE-2026-34481

CVSS scores:

* CVE-2026-34477 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

* CVE-2026-34477 ( NVD ): 6.3

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2026-34477 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2026-34479 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2026-34479 ( NVD ): 6.9

Announcement ID: SUSE-SU-2026:1843-1
Release Date: 2026-05-13T15:24:58Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here