Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-3337

Опубликовано: 02 мар. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

A flaw was found in AWS-LC. This vulnerability, a timing discrepancy, allows an unauthenticated attacker to potentially determine the validity of an authentication tag. This information disclosure could be exploited through timing analysis.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Confidential Compute Attestationopenshift-sandboxed-containers/osc-monitor-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-operator-bundleFix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-payload-rhel9Fix deferred
Confidential Compute Attestationopenshift-sandboxed-containers/osc-rhel9-operatorFix deferred
Red Hat Enterprise Linux 10clevis-pin-trusteeFix deferred
Red Hat Enterprise Linux 10trusteeFix deferred
Red Hat Enterprise Linux 10virt-firmware-rsFix deferred
Red Hat Enterprise Linux 9clevis-pin-trusteeFix deferred
Red Hat OpenShift Container Platform 4kata-containersFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-208
https://bugzilla.redhat.com/show_bug.cgi?id=2444024aws-lc: AWS-LC: Information disclosure via timing discrepancy in AES-CCM decryption

EPSS

Процентиль: 8%
0.00027
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
nvd
24 дня назад

Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.

EPSS

Процентиль: 8%
0.00027
Низкий

6.5 Medium

CVSS3