CVE-2026-3338

Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:amazon:aws-lc-sys:*:*:*:*:*:rust:*:*
cpe:2.3:a:amazon:aws_libcrypto:*:*:*:*:*:*:*:*

History

11 Mar 2026, 16:54

Type Values Removed Values Added
CPE cpe:2.3:a:aws:aws_libcrypto:*:*:*:*:*:*:*:* cpe:2.3:a:amazon:aws_libcrypto:*:*:*:*:*:*:*:*
cpe:2.3:a:amazon:aws-lc-sys:*:*:*:*:*:rust:*:*
First Time Amazon aws-lc-sys
Amazon
Amazon aws Libcrypto

11 Mar 2026, 14:12

Type Values Removed Values Added
References () https://aws.amazon.com/security/security-bulletins/2026-005-AWS/ - () https://aws.amazon.com/security/security-bulletins/2026-005-AWS/ - Vendor Advisory
References () https://github.com/aws/aws-lc/releases/tag/v1.69.0 - () https://github.com/aws/aws-lc/releases/tag/v1.69.0 - Release Notes
References () https://github.com/aws/aws-lc/security/advisories/GHSA-jchq-39cv-q4wj - () https://github.com/aws/aws-lc/security/advisories/GHSA-jchq-39cv-q4wj - Vendor Advisory
First Time Aws aws Libcrypto
Aws
CPE cpe:2.3:a:aws:aws_libcrypto:*:*:*:*:*:*:*:*
Summary
  • (es) La validación de firma incorrecta en PKCS7_verify() en AWS-LC permite a un usuario no autenticado eludir la verificación de firma al procesar objetos PKCS7 con atributos autenticados. Los clientes de los servicios de AWS no necesitan tomar ninguna medida. Las aplicaciones que utilizan AWS-LC deberían actualizarse a la versión 1.69.0 de AWS-LC.

02 Mar 2026, 23:16

Type Values Removed Values Added
References
  • () https://github.com/aws/aws-lc/security/advisories/GHSA-jchq-39cv-q4wj -

02 Mar 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 22:16

Updated : 2026-03-11 16:54


NVD link : CVE-2026-3338

Mitre link : CVE-2026-3338

CVE.ORG link : CVE-2026-3338


JSON object : View

Products Affected

amazon

  • aws_libcrypto
  • aws-lc-sys
CWE
CWE-347

Improper Verification of Cryptographic Signature