CVE-2026-85656
massLocal root command injection in Amazon Linux log4j-cve-2021-44228-hotpatch package
The log4j-cve-2021-44228-hotpatch package that Amazon shipped for Amazon Linux to mitigate the Log4Shell vulnerability (CVE-2021-44228) itself contains an OS command injection flaw (CWE-78). A local user can trigger the flaw when a Java process has an executable path containing embedded newline characters, which the hotpatch tooling fails to handle safely when constructing its commands. Successful exploitation allows the local user to execute arbitrary commands with root privileges, yielding a full local privilege escalation. Any Amazon Linux system with the hotpatch package installed at a version before 1.3-9 is affected. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 1.1%, so no active exploitation is currently known.
What to do: Update the log4j-cve-2021-44228-hotpatch package to 1.3-9 or later using your normal Amazon Linux package update mechanism, and verify the installed version with a package query (e.g., rpm -q). Inventory which instances have the hotpatch package installed, prioritizing multi-user systems where local accounts are less trusted, since exploitation requires a local user plus a Java process whose executable path contains embedded newlines. Note that the hotpatch was a Log4Shell mitigation, so if it is removed or superseded, confirm your Java runtimes are instead running patched log4j versions.
| Amazon (AWS) log4j-cve-2021-44228-hotpatch package for Amazon Linux | all versions before 1.3-9 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.