CVE-2026-85656

7.8

Amazon · log4j-cve-2021-44228-hotpatch

A local OS command injection vulnerability exists in the Amazon Linux log4j-cve-2021-44228-hotpatch package, potentially allowing local users to gain root privileges.

Executive summary

A high-severity command injection vulnerability in the Amazon Linux log4j-cve-2021-44228-hotpatch package allows local authenticated users to execute arbitrary commands with root privileges.

Vulnerability

This flaw involves an OS command injection (CWE-78) triggered by a Java process executable path containing embedded newline characters. The vulnerability requires the attacker to have local access (PR:L) to the system.

Business impact

The vulnerability carries a CVSS score of 7.8, indicating a high level of risk due to the potential for full system compromise. An attacker who successfully exploits this flaw can elevate their privileges to root, leading to total control over the affected server, potential data exfiltration, and the ability to install persistent malware or disrupt critical business services.

Remediation

Immediate Action: Update the log4j-cve-2021-44228-hotpatch package to version 1.3-9.amzn2 or later immediately to resolve the injection vulnerability.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or attempts to execute commands with unexpected input parameters.

Compensating Controls: Ensure that local access is strictly controlled and audited, as this vulnerability requires a local user account to trigger the exploit.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high-severity nature of this flaw and the potential for privilege escalation to root, administrators must treat this as a priority update. Apply the provided patch version 1.3-9.amzn2 to all affected Amazon Linux instances immediately to neutralize the command injection risk.

More Amazon CVEs all →

Sources