Skip to content

RUSTSEC-2026-0047: PKCS7_verify Signature Validation Bypass in AWS-LC #421

@github-actions

Description

@github-actions
Details
Package aws-lc-sys
Version 0.37.1
URL https://aws.amazon.com/security/security-bulletins/2026-005-AWS
Patched Versions >=0.38.0
Unaffected Versions <0.24.0
Aliases CVE-2026-3338, GHSA-hfpc-8r3f-gw53, GHSA-jchq-39cv-q4wj

Improper signature validation in PKCS7_verify() in AWS-LC allows an
unauthenticated user to bypass signature verification when processing PKCS7
objects with Authenticated Attributes.

Customers of AWS services do not need to take action. aws-lc-sys contains
code from AWS-LC. Applications using aws-lc-sys should upgrade to the most
recent release of aws-lc-sys.

There is no workaround; applications using aws-lc-sys should upgrade to the
most recent release of aws-lc-sys.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions