Security Advisory

CVE-2026-85656

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-04 17:33:20
Last updated 2026-09-04 17:49:26
Assigner AMZN
CVSS score 8.5
State PUBLISHED

Description

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedded newline characters.