CVE-2026-85656: OS command injection in Amazon log4j-cve-2021-44228-hotpatch
An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Linux log4j-cve-2021-44228-hotpatchto a version that resolves this vulnerability.Fixed in 1.3-9
Event History
Frequently Asked Questions
Who can exploit this issue?
A local user with existing low-privileged access can exploit it. The vulnerable condition involves a Java process whose executable path contains embedded newline characters.
What level of access could exploitation provide?
Successful exploitation might allow the local attacker to execute arbitrary operating-system commands with root privileges.
Which package versions need remediation?
Amazon Linux systems using log4j-cve-2021-44228-hotpatch before version 1.3-9 are affected. Update the package to version 1.3-9 or later.