CVE-2026-3338: PKCS7_verify Signature Validation Bypass in AWS-LC
Improper signature validation in PKCS7verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes.
Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AWS-LCto a version that resolves this vulnerability.Fixed in 1.69.0Patch CVE-2026-3336
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3338?
CVE-2026-3338 is classified as a vulnerability with the potential for significant impact due to the bypass of signature verification.
How do I fix CVE-2026-3338?
To fix CVE-2026-3338, upgrade to AWS-LC version 1.69.0 or later.
Who is affected by CVE-2026-3338?
AWS-LC versions prior to 1.69.0 are affected by CVE-2026-3338.
Can unprivileged users exploit CVE-2026-3338?
Yes, CVE-2026-3338 allows an unauthenticated user to bypass signature validation.
Is there an official advisory for CVE-2026-3338?
Yes, AWS has released a security bulletin regarding CVE-2026-3338 that provides further details on the issue.