-
-
Notifications
You must be signed in to change notification settings - Fork 70
Open
Description
| Details | |
|---|---|
| Package | aws-lc-sys |
| Version | 0.37.1 |
| URL | https://aws.amazon.com/security/security-bulletins/2026-005-AWS |
| Patched Versions | >=0.38.0 |
| Unaffected Versions | <0.24.0 |
| Aliases | CVE-2026-3336, GHSA-cfwj-9wp5-wqvp, GHSA-vw5v-4f2q-w9xf |
Improper certificate validation in PKCS7_verify() in AWS-LC allows an
unauthenticated user to bypass certificate chain verification when processing
PKCS7 objects with multiple signers, except the final signer.
Customers of AWS services do not need to take action. aws-lc-sys contains
code from AWS-LC. Applications using aws-lc-sys should upgrade to the most
recent release of aws-lc-sys.
There is no workaround; applications using aws-lc-sys should upgrade to the
most recent release of aws-lc-sys.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels