https://seclists.org/oss-sec/2026/q1/252: Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338)
Published Mar 3, 2026
·Updated
Affected Software
3 affected components
github/aws-lc>=1.41.0<1.69.0, >=AWS-LC-FIPS-3.0.0<AWS-LC-FIPS-3.2.0
github/aws-lc-sys>=0.24.0<0.38.0, >=0.14.0<0.38.0
github/aws-lc-sys-fips>=0.13.0<0.13.12
Frequently Asked Questions
1
What is the severity of CVE-2026-3336?
CVE-2026-3336 is classified with high severity due to its potential impact on cryptographic operations.
2
How do I fix CVE-2026-3336?
To fix CVE-2026-3336, update the AWS-LC library to the latest version that includes the security patch.
3
What are the affected versions for CVE-2026-3337?
CVE-2026-3337 affects specific versions of the AWS-LC library prior to the security patch release.
4
What impact does CVE-2026-3338 have on applications?
CVE-2026-3338 could lead to vulnerabilities that compromise the integrity of encrypted data in applications using the library.
5
Are there any workarounds for CVE-2026-3337 until a patch is available?
While specific workarounds are limited, it is recommended to avoid using the affected features until an update is applied.