Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3336

Опубликовано: 02 мар. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

A flaw was found in aws-lc, a cryptographic library. An unauthenticated attacker can exploit improper certificate validation within the PKCS7_verify() function. This allows them to bypass the verification process for certificate chains when handling PKCS7 objects that contain multiple digital signers, except for the last one. The primary consequence is a compromise of integrity, as the system may incorrectly trust unverified certificates.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleAffected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorAffected
Red Hat Enterprise Linux 10clevis-pin-trusteeWill not fix
Red Hat Enterprise Linux 10trusteeWill not fix
Red Hat Enterprise Linux 10virt-firmware-rsAffected
Red Hat Enterprise Linux 9clevis-pin-trusteeWill not fix
Red Hat OpenShift Container Platform 4kata-containersAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2444026aws-lc: aws-lc: Certificate validation bypass via improper handling of PKCS7 objects

EPSS

Процентиль: 1%
0.0001
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
24 дня назад

Improper certificate validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass certificate chain verification when processing PKCS7 objects with multiple signers, except the final signer. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

msrc
21 день назад

PKCS7_verify Certificate Chain Validation Bypass in AWS-LC

EPSS

Процентиль: 1%
0.0001
Низкий

7.5 High

CVSS3