Race Condition Affecting log4j-cve-2021-44228-hotpatch package, versions <0:1.3-5.amzn1


Severity

Recommended
0.0
high
0
10

Based on Amazon Linux security rating.

Threat Intelligence

EPSS
0.03% (6th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Race Condition vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-AMZN201803-LOG4JCVE202144228HOTPATCH-2871838
  • published16 Jun 2022
  • disclosed17 Jun 2022

Introduced: 16 Jun 2022

CVE-2022-33915  (opens in a new tab)
CWE-362  (opens in a new tab)

How to fix?

Upgrade Amazon-Linux:2018.03 log4j-cve-2021-44228-hotpatch to version 0:1.3-5.amzn1 or higher.
This issue was patched in ALAS-2022-1601.

NVD Description

Note: Versions mentioned in the description apply only to the upstream log4j-cve-2021-44228-hotpatch package and not the log4j-cve-2021-44228-hotpatch package as distributed by Amazon-Linux. See How to fix? for Amazon-Linux:2018.03 relevant fixed versions and status.

Versions of the Amazon AWS Apache Log4j hotpatch package before log4j-cve-2021-44228-hotpatch-1.3.5 are affected by a race condition that could lead to a local privilege escalation. This Hotpatch package is not a replacement for updating to a log4j version that mitigates CVE-2021-44228 or CVE-2021-45046; it provides a temporary mitigation to CVE-2021-44228 by hotpatching the local Java virtual machines. To do so, it iterates through all running Java processes, performs several checks, and executes the Java virtual machine with the same permissions and capabilities as the running process to load the hotpatch. A local user could cause the hotpatch script to execute a binary with elevated privileges by running a custom java process that performs exec() of an SUID binary after the hotpatch has observed the process path and before it has observed its effective user ID.

CVSS Base Scores

version 3.1