CVE-2026-4428: CRL Distribution Point Scope Check Logic Error in AWS-LC
A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks.
To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4428?
CVE-2026-4428 is considered a high-severity vulnerability due to its potential to allow revoked certificates to bypass certificate revocation checks.
How do I fix CVE-2026-4428?
To remediate CVE-2026-4428, upgrade your AWS-LC to version 1.71.0 or later, or AWS-LC-FIPS to version 3.3.0 or later.
What software is affected by CVE-2026-4428?
CVE-2026-4428 affects Amazon AWS-LC versions prior to 1.71.0 and AWS-LC-FIPS versions prior to 3.3.0.
What does CVE-2026-4428 exploit?
CVE-2026-4428 exploits a logic error in CRL distribution point validation, leading to incorrect rejection of partitioned CRLs.
When was CVE-2026-4428 disclosed?
CVE-2026-4428 has been disclosed in security bulletins and released notes, with the fix available since version 1.71.0.