Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Update to log4cxx 1.7.0. New features: fallback-ref appender attribute, Qt CMake find_package component, TelnetAppender NonBlocking option. Bug fixes: non-ASCII JSON encoding, invalid XML 1.0 characters in XML output, crash on recursive XML config references, possible UB during. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-43767b6007 2026-07-12 01:10:38.798594+00:00 -------------------------------------------------------------------------------- Name : log4cxx Product : Fedora 44 Version : 1.7.0 Release : 2.fc44 URL : http://logging.apache.org/log4cxx/index.html Summary : A port to C++ of the Log4j project Description : Log4cxx is a popular logging package written in C++. One of its distinctive features is the notion of inheritance in loggers. Using a logger hierarchy it is possible to control which log statements are output at arbitrary granularity. This helps reduce the volume of logged output and minimize the cost of logging. -------------------------------------------------------------------------------- Update Information: Update to log4cxx 1.7.0. New features: fallback-ref appender attribute, Qt CMake find_package component, TelnetAppender NonBlocking option. Bug fixes: non-ASCII JSON encoding, invalid XML 1.0 characters in XML output, crash on recursive XML config references, possible UB during configuration changes, message loss during recursive logging, ODBCAppender prepared-statement buffer lifetimes. No ABI-relevant changes; liblog4cxx SONAME (%{sover}) is unchanged. -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Till Hofmann - 1.7.0-2 - Skip 2GB-message test on 32-bit architectures * Fri Jul 3 2026 Till Hofmann - 1.7.0-1 - Update to 1.7.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2455029 - log4cxx-1.7.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2455029 [ 2 ] Bug #2457923 - CVE-2026-40023 log4cxx: Apache Log4cxx: Log processing impairment due to unsanitized XML characters [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2457923 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-43767b6007' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Security update. Publication date: 17 Jun 2026 URL: https://advisories.mageia.org/MGASA-2026-0218.html Type: security Affected Mageia releases: 9 CVE: CVE-2026-40023 Description: CVE-2026-40023, Apache Log4cxx, Apache Log4cxx (Conan), Apache Log4cxx (Brew): Silent log event loss in XMLLayout due to unescaped XML 1.0 forbidden characters References: - https://bugs.mageia.org/show_bug.cgi?id=35352 - https://www.openwall.com/lists/oss-security/2026/04/10/12 - https://lists.opensuse.org/archives/list/
Update to 1.5.0, fix CVE-2025-54813, CVE-2025-22838. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2025-1b48c1a920 2025-10-12 01:09:51.211551+00:00 -------------------------------------------------------------------------------- Name : log4cxx Product : Fedora 41 Version : 1.5.0 Release : 1.fc41 URL : https://logging.apache.org/log4cxx/1.5.0/index.html Summary : A port to C++ of the Log4j project Description : Log4cxx is a popular logging package written in C++. One of its distinctive features is the notion of inheritance in loggers. Using a logger hierarchy it is possible to control which log statements are output at arbitrary granularity. This helps reduce the volume of logged output and minimize the cost of logging. -------------------------------------------------------------------------------- Update Information: Update to 1.5.0, fix CVE-2025-54813, CVE-2025-22838 -------------------------------------------------------------------------------- ChangeLog: * Fri Oct 3 2025 Till Hofmann - 1.5.0-1 - Update to 1.5.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2393061 - CVE-2025-54812 log4cxx: Log4cxx HTMLLayout XSS Vulnerability [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2393061 [ 2 ] Bug #2393132 - CVE-2025-54813 log4cxx: Log4cxx: Improper JSON Output Neutralization [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2393132 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-1b48c1a920' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keysused by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
Multiple vulnerabilities were discovered in log4cxx, a logging library for C++ that is compatible with the JAVA log4j framework. CVE-2025-54812 . ------------------------------------------------------------------------- Debian LTS Advisory DLA-4322-1
Get the latest Linux and open source security news straight to your inbox.