Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 512
Alerts This Week
Warning Icon 1 512

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -5 articles for you...
89

Fedora 44 log4cxx 1.7.0 Update Bug Fixes and Enhancements

Update to log4cxx 1.7.0. New features: fallback-ref appender attribute, Qt CMake find_package component, TelnetAppender NonBlocking option. Bug fixes: non-ASCII JSON encoding, invalid XML 1.0 characters in XML output, crash on recursive XML config references, possible UB during. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-43767b6007 2026-07-12 01:10:38.798594+00:00 -------------------------------------------------------------------------------- Name : log4cxx Product : Fedora 44 Version : 1.7.0 Release : 2.fc44 URL : http://logging.apache.org/log4cxx/index.html Summary : A port to C++ of the Log4j project Description : Log4cxx is a popular logging package written in C++. One of its distinctive features is the notion of inheritance in loggers. Using a logger hierarchy it is possible to control which log statements are output at arbitrary granularity. This helps reduce the volume of logged output and minimize the cost of logging. -------------------------------------------------------------------------------- Update Information: Update to log4cxx 1.7.0. New features: fallback-ref appender attribute, Qt CMake find_package component, TelnetAppender NonBlocking option. Bug fixes: non-ASCII JSON encoding, invalid XML 1.0 characters in XML output, crash on recursive XML config references, possible UB during configuration changes, message loss during recursive logging, ODBCAppender prepared-statement buffer lifetimes. No ABI-relevant changes; liblog4cxx SONAME (%{sover}) is unchanged. -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Till Hofmann - 1.7.0-2 - Skip 2GB-message test on 32-bit architectures * Fri Jul 3 2026 Till Hofmann - 1.7.0-1 - Update to 1.7.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455029 - log4cxx-1.7.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2455029 [ 2 ] Bug #2457923 - CVE-2026-40023 log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457923 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-43767b6007' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new . Enhance your Fedora experience with log4cxx 1.7.0 upgrade featuring important bug fixes and new functionalities.. log4cxx upgrade, Fedora package update, logging enhancements. . LinuxSecurity.com Team

Calendar%202 Jul 11, 2026 Fedora
203

Mageia 9 Log4cxx Critical Silent Log Event Loss Vuln 2026-0218

Security update. Publication date: 17 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0218.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-40023 Description: CVE-2026-40023, Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters References: - https://bugs.mageia.org/show_bug.cgi?id=35352 - https://www.openwall.com/lists/oss-security/2026/04/10/12 - https://lists.opensuse.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it./message/A7IXK4LCNBBYY5YSNHODMPEG64MYK6VE/ - https://www.cve.org/CVERecord?id=CVE-2026-40023 SRPMS: - 9/core/log4cxx-1.1.0-1.1.mga9 . Critical security update for Mageia affecting log4cxx due to log event loss in XMLLayout caused by unescaped characters.. Mageia Log4cxx Apache Update Security Issue CVE-2026-40023. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Jun 17, 2026 Critical Mageia
89

Fedora 41: log4cxx Important Improper JSON Output Vuln 2025-1b48c1a920

Update to 1.5.0, fix CVE-2025-54813, CVE-2025-22838. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1b48c1a920 2025-10-12 01:09:51.211551+00:00 -------------------------------------------------------------------------------- Name : log4cxx Product : Fedora 41 Version : 1.5.0 Release : 1.fc41 URL : https://logging.apache.org/log4cxx/1.5.0/index.html Summary : A port to C++ of the Log4j project Description : Log4cxx is a popular logging package written in C++. One of its distinctive features is the notion of inheritance in loggers. Using a logger hierarchy it is possible to control which log statements are output at arbitrary granularity. This helps reduce the volume of logged output and minimize the cost of logging. -------------------------------------------------------------------------------- Update Information: Update to 1.5.0, fix CVE-2025-54813, CVE-2025-22838 -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 3 2025 Till Hofmann - 1.5.0-1 - Update to 1.5.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2393061 - CVE-2025-54812 log4cxx: Log4cxx HTMLLayout XSS Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2393061 [ 2 ] Bug #2393132 - CVE-2025-54813 log4cxx: Log4cxx: Improper JSON Output Neutralization [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2393132 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1b48c1a920' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- This email address is being protected from spambots. You need JavaScript enabled to view it. To unsubscribe send an email to This email address is being protected from spambots. You need JavaScript enabled to view it. Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/This email address is being protected from spambots. You need JavaScript enabled to view it. Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue . Fedora 41 update resolves critical log4cxx issues with CVE-2025-54813 and CVE-2025-22838 for enhanced security.. log4cxx update, Fedora 41 security, CVE-2025-54813, CVE-2025-22838. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Oct 12, 2025 Important Fedora
197

Debian 11: DLA-4322-1 log4cxx Critical HTML JSON Injection CVE-2025-54812

Multiple vulnerabilities were discovered in log4cxx, a logging library for C++ that is compatible with the JAVA log4j framework. CVE-2025-54812 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4322-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Lukas Märdian October 05, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : log4cxx Version : 0.11.0-2+deb11u1 CVE ID : CVE-2025-54812 CVE-2025-54813 Debian Bug : 1111879 1111881 Multiple vulnerabilities were discovered in log4cxx, a logging library for C++ that is compatible with the JAVA log4j framework. CVE-2025-54812 When using HTMLLayout, logger names are not properly escaped when writing out to the HTML file. If untrusted data is used to retrieve the name of a logger, an attacker could theoretically inject HTML or Javascript in order to hide information from logs or steal data from the user. CVE-2025-54813 When using JSONLayout, not all payload bytes are properly escaped. If an attacker-supplied message contains certain non-printable characters, these will be passed along in the message and written out as part of the JSON message. This may prevent applications that consume these logs from correctly interpreting the information within them. For Debian 11 bullseye, these problems have been fixed in version 0.11.0-2+deb11u1. We recommend that you upgrade your log4cxx packages. For the detailed security status of log4cxx please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/log4cxx Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS: Critical log4cxx updateaddresses multiple security issues affecting logging functionalities for C++ applications.. Debian LTS, log4cxx, security update, logging library, critical vulnerabilities. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Oct 04, 2025 Critical Debian LTS
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":3,"type":"x","order":2,"pct":60,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":2,"type":"x","order":4,"pct":40,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200