Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3336

Опубликовано: 02 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

A flaw was found in aws-lc, a cryptographic library. An unauthenticated attacker can exploit improper certificate validation within the PKCS7_verify() function. This allows them to bypass the verification process for certificate chains when handling PKCS7 objects that contain multiple digital signers, except for the last one. The primary consequence is a compromise of integrity, as the system may incorrectly trust unverified certificates.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleNot affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Not affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorNot affected
Red Hat Enterprise Linux 10clevis-pin-trusteeWill not fix
Red Hat Enterprise Linux 10trusteeWill not fix
Red Hat Enterprise Linux 10virt-firmware-rsNot affected
Red Hat Enterprise Linux 9clevis-pin-trusteeWill not fix
Red Hat OpenShift Container Platform 4kata-containersAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2444026aws-lc: aws-lc: Certificate validation bypass via improper handling of PKCS7 objects

EPSS

Процентиль: 51%
0.00771
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

msrc
5 месяцев назад

PKCS7_verify Certificate Chain Validation Bypass in AWS-LC

EPSS

Процентиль: 51%
0.00771
Низкий

7.5 High

CVSS3