CVE-2026-85656 - OS command injection in Amazon log4j-cve-2021-44228-hotpatch
Cybersecurity Classified by Officially
CVE-2026-85656 - OS command injection in Amazon log4j-cve-2021-44228-hotpatch
Bulletin ID: 2026-098-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/04/2026 10:30 AM PDT
log4j-cve-2021-44228-hotpatch is a tool which injects a Java agent into a running JVM process. The agent will attempt to patch the lookup() method of all loaded org.apache.logging.log4j.core.lookup.JndiLookup instances to unconditionally return the string "Patched JndiLookup::lookup()". It is designed to address the CVE-2021-44228 remote code execution issue in Log4j without restarting the Java process. We identified CVE-2026-85656, an OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9.amzn2 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
This issue has been addressed in log4j-cve-2021-44228-hotpatch version 1.3-9.amzn2. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Run yum update log4j-cve-2021-44228-hotpatch or yum update --advisory ALAS2-2026-3784 to update your system.
This is an extract. The publication continues at the source.
Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-098-aws/
Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Amazon Web Services — imported from official source
- Official source
- https://aws.amazon.com/security/security-bulletins/feed/ RSS
- Imported
- September 18, 2026 09:42
- Versions
- 1 recorded
- Identity
-
a6adea1d9656c0b694868242bf3288bb293121cb