CVE-2026-3337: Timing Side-Channel in AES-CCM Tag Verification in AWS-LC
Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis.
The impacted implementations are through the EVP CIPHER API: EVPaes128ccm, EVPaes192ccm, and EVPaes256ccm.
Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3337?
CVE-2026-3337 is considered a high-severity vulnerability due to its potential for allowing unauthenticated users to exploit timing side-channels in AES-CCM decryption.
How do I fix CVE-2026-3337?
To remediate CVE-2026-3337, upgrade to AWS-LC version 1.69.0 or later, which addresses the timing discrepancy issue.
What impact does CVE-2026-3337 have on systems using AWS-LC?
CVE-2026-3337 can enable attackers to perform timing analysis and potentially infer the validity of authentication tags during AES-CCM decryption.
Is CVE-2026-3337 exploitable remotely?
Yes, CVE-2026-3337 is exploitable by unauthenticated users, making systems vulnerable to remote attacks.
What software is affected by CVE-2026-3337?
CVE-2026-3337 affects implementations of AWS-LC up to version 1.69.0, specifically those using the EVP CIPHER API.