Amazon Linux 2 Security Advisory: ALASCORRETTO8-2021-001
Advisory Release Date: 2021-12-17 18:31 Pacific
Advisory Updated Date: 2021-12-17 22:58 Pacific
No versions of an Amazon Linux Java Virtual Machine (JVM) are affected by CVE-2021-44228 or CVE-2021-45046. However, if customers load a log4j version that is affected by CVE-2021-44228 or CVE-2021-45046 into an Amazon Linux JVM, it will introduce the issues identified in CVE-2021-44228 and CVE-2021-45046 into the JVM. This update modifies Amazon Linux packages that provide a JVM to also install the AWS-developed hotpatch to mitigate CVE-2021-44228 or CVE-2021-45046 by default. For more information on the hotpatch package in Amazon Linux, see https://alas.aws.amazon.com/announcements/2021-001.html
Affected Packages:
java-1.8.0-amazon-corretto
Note:
This advisory is applicable to Amazon Linux 2 - Corretto8 Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update java-1.8.0-amazon-corretto to update your system.
aarch64:
java-1.8.0-amazon-corretto-1.8.0_312.b07-2.amzn2.aarch64
java-1.8.0-amazon-corretto-devel-1.8.0_312.b07-2.amzn2.aarch64
src:
java-1.8.0-amazon-corretto-1.8.0_312.b07-2.amzn2.src
x86_64:
java-1.8.0-amazon-corretto-1.8.0_312.b07-2.amzn2.x86_64
java-1.8.0-amazon-corretto-devel-1.8.0_312.b07-2.amzn2.x86_64