Executive brief
AWS-LC is a cryptographic library used by applications to secure data and verify digital signatures. A flaw in this library allows attackers to provide specially crafted files that appear to be legitimately signed even if they are not. This could allow an attacker to bypass security checks, potentially leading to the installation of malicious software or the acceptance of forged digital documents.
Technical details
A vulnerability exists in the PKCS7_verify() function of the AWS-LC cryptographic library due to improper certificate validation. When processing PKCS7 objects containing multiple signers, the library fails to verify the certificate chains for all signers except the final one. A remote, unauthenticated attacker can exploit this by crafting a PKCS7 object with multiple signers where intermediate signers have invalid or untrusted chains, effectively bypassing intended security identity checks. The issue is resolved in AWS-LC version 1.69.0 and aws-lc-sys version 0.38.0.
Affected products
- AWS AWS-LC >= v1.41.0, < v1.69.0
- AWS aws-lc-sys >= v0.24.0, < v0.38.0
- Red Hat Red Hat Trusted Artifact Signer 1.3
- Red Hat Red Hat Enterprise Linux 9, 10
- Red Hat Red Hat OpenShift Container Platform 4
CVE identifiers
- CVE-2026-3336
- CVE-2026-3338
- CVE-2026-3337
Timeline
- 2026-03-02: advisory: Initial advisory published by AWS and GitHub Security Advisory created.
- 2026-03-02: patched: AWS-LC v1.69.0 released.
- 2026-03-23: advisory: Red Hat published security advisory RHSA-2026:5459.
References
- https://aws.amazon.com/security/security-bulletins/2026-005-AWS/
- https://github.com/aws/aws-lc/releases/tag/v1.69.0
- https://github.com/aws/aws-lc/security/advisories/GHSA-cfwj-9wp5-wqvp
- https://access.redhat.com/errata/RHSA-2026:5459
- https://access.redhat.com/security/cve/CVE-2026-3336
- https://bugzilla.redhat.com/show_bug.cgi?id=2444026
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3336.json