ZeroHour

CVE-2026-85656

mass

Local root command injection in Amazon Linux log4j-cve-2021-44228-hotpatch package

CVSS 4.0
8.5 high
EPSS
1%p64
Published
()
Modified
AI analysis

The log4j-cve-2021-44228-hotpatch package that Amazon shipped for Amazon Linux to mitigate the Log4Shell vulnerability (CVE-2021-44228) itself contains an OS command injection flaw (CWE-78). A local user can trigger the flaw when a Java process has an executable path containing embedded newline characters, which the hotpatch tooling fails to handle safely when constructing its commands. Successful exploitation allows the local user to execute arbitrary commands with root privileges, yielding a full local privilege escalation. Any Amazon Linux system with the hotpatch package installed at a version before 1.3-9 is affected. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at about 1.1%, so no active exploitation is currently known.

What to do: Update the log4j-cve-2021-44228-hotpatch package to 1.3-9 or later using your normal Amazon Linux package update mechanism, and verify the installed version with a package query (e.g., rpm -q). Inventory which instances have the hotpatch package installed, prioritizing multi-user systems where local accounts are less trusted, since exploitation requires a local user plus a Java process whose executable path contains embedded newlines. Note that the hotpatch was a Log4Shell mitigation, so if it is removed or superseded, confirm your Java runtimes are instead running patched log4j versions.

Affected
Amazon (AWS) log4j-cve-2021-44228-hotpatch package for Amazon Linuxall versions before 1.3-9
Estimated exposure
massplausibly hundreds of thousands to millions of Amazon Linux instances have the hotpatch package installed — Amazon Linux is one of the most widely used operating systems on AWS EC2 (millions of instances) and the hotpatch was distributed through standard Amazon Linux repositories during the Log4Shell mitigation push, though only hosts actually…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.

Weakness
CWE-78
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.