CVE-2026-85656 - OS command injection in Amazon log4j-cve-2021-44228-hotpatch
Bulletin ID: 2026-098-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/04/2026 10:30 AM PDT
Description:
log4j-cve-2021-44228-hotpatch is a tool which injects a Java agent into a running JVM process. The agent will attempt to patch the lookup() method of all loaded org.apache.logging.log4j.core.lookup.JndiLookup instances to unconditionally return the string "Patched JndiLookup::lookup()". It is designed to address the CVE-2021-44228 remote code execution issue in Log4j without restarting the Java process. We identified CVE-2026-85656, an OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9.amzn2 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.
Impacted versions: <=1.3-8.amzn2
Resolution:
This issue has been addressed in log4j-cve-2021-44228-hotpatch version 1.3-9.amzn2. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
Run yum update log4j-cve-2021-44228-hotpatch or yum update --advisory ALAS2-2026-3784 to update your system.
References:
Please email aws-security@amazon.com with any security questions or concerns.