logo

AWS-LC Flaw Exposes Amazon Users to Attacks by Bypassing Certificate Chain Validation

ID: f729e4cf-93d5-524b-ba49-b4edfca347d0

STIX ID: report--f729e4cf-93d5-524b-ba49-b4edfca347d0

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-03-06

Date Updated: 2026-04-22

Author: Divya

...
...

Amazon published security bulletin 2026-005-AWS describing three high-severity vulnerabilities in the AWS-LC cryptographic library—two PKCS7-related certificate/signature validation bypasses and an AES-CCM timing side-channel (CVE-2026-3336, CVE-2026-3337, CVE-2026-3338). The flaws affect a broad range of AWS-LC and aws-lc-sys versions (including some FIPS builds); Amazon released patches in v1.69.0 and related package updates and recommends immediate patching, noting no workaround for the PKCS7 bypasses and a limited temporary mitigation for the timing issue via specific EVP AEAD configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.