Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 462
Alerts This Week
Warning Icon 1 462

SUSE 2026-1843-1 Log4j Moderate Vulnerability With Four Key Fixes

suse
Calendar Grey May 13, 2026
Scroller Suse
An update for log4j addresses multiple vulnerabilities. Crucial for maintaining system integrity and security.
An update that solves four vulnerabilities can now be installed.

Summary

## This update for log4j fixes the following issues: * CVE-2026-34477: TLS connections vulnerable to interception due to incomplete hostname verification configuration checks (bsc#1262050). * CVE-2026-34479: silent log event loss due to improper XML escaping in `Log4j1XmlLayout` (bsc#1262091). * CVE-2026-34480: silent log event loss due to improper XML escaping in `XmlLayout` (bsc#1262092). * CVE-2026-34481: silent log event loss due to improper serialization of non- finite floating-point values in `JsonTemplateLayout` (bsc#1262093). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7

References

* bsc#1262050

* bsc#1262091

* bsc#1262092

* bsc#1262093

Cross-

* CVE-2026-34477

* CVE-2026-34479

* CVE-2026-34480

* CVE-2026-34481

CVSS scores:

* CVE-2026-34477 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N

* CVE-2026-34477 ( NVD ): 6.3

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

* CVE-2026-34477 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

* CVE-2026-34479 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

* CVE-2026-34479 ( NVD ): 6.9

Announcement ID: SUSE-SU-2026:1843-1
Release Date: 2026-05-13T15:24:58Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.