{"id":"CVE-2026-3338","summary":"PKCS7_verify Signature Validation Bypass in AWS-LC","details":"Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes.\n\n\n\nCustomers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.","aliases":["GHSA-hfpc-8r3f-gw53","GHSA-jchq-39cv-q4wj","RUSTSEC-2026-0047"],"modified":"2026-08-22T09:15:42.456807Z","published":"2026-03-02T21:22:41.954Z","database_specific":{"cna_assigner":"AMZN","cwe_ids":["CWE-347"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3338.json"},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-3338.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:5459"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-3338"},{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/2026-005-AWS/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/3xxx/CVE-2026-3338.json"},{"type":"ADVISORY","url":"https://github.com/aws/aws-lc/security/advisories/GHSA-jchq-39cv-q4wj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-3338"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2444025"},{"type":"FIX","url":"https://github.com/aws/aws-lc/releases/tag/v1.69.0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/aws/aws-lc","events":[{"introduced":"dd5948b5a55f5dc5f0db9bbfa0e21c35d9e820e2"},{"fixed":"37d86461a95782fd5d8b77873f9e1cb134ea2f95"}],"database_specific":{"cpe":"cpe:2.3:a:amazon:aws_libcrypto:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.41.0"},{"fixed":"1.69.0"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"versions":["v1.58.1","v1.68.0","v1.67.0","v1.66.2","v1.66.1","v1.66.0","AWS-LC-FIPS-NETOS-v1.29.1","v1.65.1","v1.65.0","v1.64.0","v1.63.0","v1.62.1","v1.62.0","v1.61.4","v1.61.3","v1.61.2","v1.61.1","v1.61.0","v1.60.0","v1.59.0","v1.58.0","v1.57.1","v1.57.0","v1.56.0","v1.55.0","v1.54.0","v1.53.1","v1.53.0","v1.52.1","v1.52.0","v1.51.2","v1.51.1","v1.51.0","v1.50.1","v1.50.0","v1.49.1","v1.49.0","v1.48.5","v1.48.4","v1.48.3","v1.48.2","v1.48.1","v1.48.0","v1.47.0","v1.46.1","v1.46.0","v1.45.0","v1.44.0","v1.43.0","v1.42.0","v1.41.1","v1.41.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-3338.json","vanir_signatures_modified":"2026-08-22T09:15:42Z","vanir_signatures":[{"id":"CVE-2026-3338-855e3c0b","signature_type":"Line","signature_version":"v1","source":"https://github.com/aws/aws-lc/commit/37d86461a95782fd5d8b77873f9e1cb134ea2f95","target":{"file":"crypto/pkcs7/pkcs7.c"},"deprecated":false,"digest":{"line_hashes":["280062061547051961335040704369984099310","59664889025735122861240116516903930146","186491128754061308478941699848016839286","44181818329089001225657707026569626534","282671460555005303787248492658194669900","44166289732973386761265031133498341556","69817426707179551398336772625900832321","239604874112229803444893855053965253409"],"threshold":0.9}},{"target":{"file":"crypto/pkcs7/pkcs7.c","function":"pkcs7_signature_verify"},"deprecated":false,"digest":{"function_hash":"158135805622728784577576606639969624490","length":2013},"id":"CVE-2026-3338-dc456f72","signature_type":"Function","signature_version":"v1","source":"https://github.com/aws/aws-lc/commit/37d86461a95782fd5d8b77873f9e1cb134ea2f95"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}