Executive brief
Amazon's log4j-cve-2021-44228-hotpatch is a tool that patches the Log4j vulnerability in running Java applications without requiring a restart. A command injection flaw in versions before 1.3-9 allows a local attacker to execute arbitrary commands with root privileges if a Java process's executable path contains embedded newline characters, potentially compromising entire systems running affected Amazon Linux instances.
Technical details
The vulnerability is an OS command injection issue in the log4j-cve-2021-44228-hotpatch package versions before 1.3-9.amzn2. The root cause lies in improper sanitization of Java process executable paths when injecting the patching agent into running JVM processes. An attacker with local access can exploit this by crafting a Java executable path containing embedded newline characters to break out of the intended command context and execute arbitrary shell commands. This vulnerability requires local access to the system but achieves privilege escalation to root. The issue has been patched in version 1.3-9.amzn2 and users are advised to update immediately.
Affected products
- Amazon log4j-cve-2021-44228-hotpatch before 1.3-9.amzn2
- Amazon Linux 2 before 1.3-9.amzn2
Timeline
- 2026-09-04: disclosed
- 2026-07-08: advisory: Amazon Linux 2 advisory ALAS2-2026-3784 released
- 2026-09-21: advisory: CVE-2026-85656 added to advisory
- 2026-09-04: patched: Fixed in log4j-cve-2021-44228-hotpatch version 1.3-9.amzn2