CVE-2026-3336: PKCS7_verify Certificate Chain Validation Bypass in AWS-LC
Improper certificate validation in PKCS7verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.
Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AWS-LCto a version that resolves this vulnerability.Fixed in 1.69.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3336?
CVE-2026-3336 is classified as a high severity vulnerability due to its potential to bypass certificate chain verification.
How do I fix CVE-2026-3336?
To fix CVE-2026-3336, upgrade to AWS-LC version 1.69.0 or later.
Who is affected by CVE-2026-3336?
CVE-2026-3336 affects users of AWS-LC versions prior to 1.69.0.
What kind of attack can CVE-2026-3336 facilitate?
CVE-2026-3336 can facilitate man-in-the-middle attacks by allowing unauthenticated users to bypass certificate validation.
What is the impact of exploiting CVE-2026-3336?
Exploiting CVE-2026-3336 can lead to compromised data integrity when processing PKCS7 objects.