Where
-Infinity
0

Via AWS Security Bulletin

https://github.com/aws/aws-lc

----- Forwarded message from "Latest Bulletins: Amazon Web Services" <aws () amazon com> ----- Date: Tue, 03 Mar 2026 09:30:01 -0000 From: "Latest Bulletins: Amazon Web Services" <aws () amazon com> To: jschauma () netmeister org Subject: Issue with AWS-LC: an open-source, general-purpose cryptographic library (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338)

Bulletin ID: 2026-005-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/02 14:30 PM PST

Description:

AWS-LC is an open-source, general-purpose cryptographic library. We identified three distinct issues:

\- CVE-2026-3336: PKCS7verify Certificate Chain Validation Bypass in AWS-LC Improper certificate validation in PKCS7verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. \- CVE-2026-3337: Timing Side-Channel in AES-CCM Tag Verification in AWS-LC Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. \- CVE-2026-3338: PKCS7verify Signature Validation bypass in AWS-LC Improper signature validation in PKCS7verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes.

Impacted versions:

\- PKCS7verify Certificate Chain Validation Bypass in AWS-LC >= v1.41.0, < v1.69.0 \- PKCS7verify Certificate Chain Validation Bypass in aws-lc-sys >= v0.24.0, < v0.38.0 \- Timing Side-Channel in AES-CCM Tag Verification in AWS-LC >= v1.21.0, < v1.69.0 \- Timing Side-Channel in AES-CCM Tag Verification in AWS-LC >= AWS-LC- FIPS-3.0.0, < AWS-LC-FIPS-3.2.0 \- Timing Side-Channel in AES-CCM Tag Verification in aws-lc-sys >= v0.14.0, < v0.38.0 \- Timing Side-Channel in AES-CCM Tag Verification in aws-lc-sys-fips >= v0.13.0, < v0.13.12 \- PKCS7verify Signature Validation bypass in AWS-LC >= v1.41.0, < v1.69.0 \- PKCS7verify Signature Validation bypass in aws-lc-sys >= v0.24.0, < v0.38.0

Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

URL: https://aws.amazon.com/security/security-bulletins/rss/2026-005-aws/ ----- End forwarded message -----

Severity
8.2
EPSS
0.03%
AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis.

The impacted implementations are through the EVP CIPHER API: EVPaes128ccm, EVPaes192ccm, and EVPaes256ccm.

Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

First published (updated )
Severity
8.7
EPSS
0.01%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Improper certificate validation in PKCS7verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer.

Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203