Junglewise Threat Intelligence

CVE-2023-32803: Amazon ca-certificates improper certificate removal in root store

CVE-2023-32803 · Severity: high · CVSS 7.5 · Published 2026-09-14

Vendors: Amazon.

Executive brief

The ca-certificates package in Amazon Linux does not properly remove certain TrustCor root certificates that were identified as potentially associated with spyware operations. An incomplete fix allows these certificates to remain in the system's trusted root store, enabling attackers to potentially issue fraudulent SSL/TLS certificates that would be accepted as legitimate by applications, compromising secure communications and enabling man-in-the-middle attacks.

Technical details

This vulnerability is a regression from an incomplete fix for CVE-2022-23491, in which TrustCor root certificates were supposed to be removed from the ca-certificates root store due to TrustCor's association with spyware. The affected ca-certificates package versions (before 2021.2.50-72 on AL2) fail to completely remove these certificates, leaving them available for certificate validation. An unauthenticated network-based attacker can exploit this by issuing forged TLS certificates signed by a retained TrustCor root certificate, which would be accepted as valid by clients relying on the incomplete root store. This enables man-in-the-middle attacks against any HTTPS connection. Patches are available via yum update ca-certificates on Amazon Linux systems.

Affected products

  • Amazon ca-certificates before 2021.2.50-72

Timeline

  • 2023-08-03: disclosed
  • 2023-08-03: patched

References