Bug 2547138 (CVE-2026-105240)
| Summary: | CVE-2026-105240 log4net-windows: log4net: Log truncation via null byte injection in OutputDebugStringAppender | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in log4net. When using the OutputDebugStringAppender on Windows, the component fails to properly neutralize null characters in log entries. An attacker whose input is written to the log can inject a null byte, causing the log record to terminate prematurely and silently drop subsequent information such as error traces. This flaw can allow attackers to conceal malicious activity or obscure critical diagnostic details.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-10-06 20:02:43 UTC
|