-
-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
PKCS7_verify Certificate Chain Validation Bypass in AWS-LC
| Details | |
|---|---|
| Package | aws-lc-sys |
| Version | 0.37.0 |
| URL | https://aws.amazon.com/security/security-bulletins/2026-005-AWS |
| Date | 2026-03-02 |
| Patched versions | >=0.38.0 |
| Unaffected versions | <0.24.0 |
Improper certificate validation in PKCS7_verify() in AWS-LC allows an
unauthenticated user to bypass certificate chain verification when processing
PKCS7 objects with multiple signers, except the final signer.
Customers of AWS services do not need to take action. aws-lc-sys contains
code from AWS-LC. Applications using aws-lc-sys should upgrade to the most
recent release of aws-lc-sys.
There is no workaround; applications using aws-lc-sys should upgrade to the
most recent release of aws-lc-sys.
See advisory page for additional details.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels