GHSA-hfpc-8r3f-gw53
AWS-LC has PKCS7_verify Signature Validation Bypass
Details
### Summary AWS-LC is an open-source, general-purpose cryptographic library.
### Impact Improper signature validation in PKCS7_verify() in AWS-LC allows an unauthenticated user to bypass signature verification when processing PKCS7 objects with Authenticated Attributes.
Customers of AWS services do not need to take action. aws-lc-sys contains code from AWS-LC. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.
#### Impacted versions: aws-lc-sys versions: >= 0.24.0, < 0.38.0
### Patches The patch is included in v0.38.0
### Workarounds There is no workaround. Applications using aws-lc-sys should upgrade to the most recent release of aws-lc-sys.
### Resources If there are any questions or comments about this advisory, contact [AWS/Amazon] Security via the [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting) or directly via email to [aws-security@amazon.com](mailto:aws-security@amazon.com). Please do not create a public GitHub issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.24.0Fixed in: 0.38.0Upgrade aws-lc-sys to 0.38.0 or newer (ecosystem crates.io).
References
- https://github.com/aws/aws-lc-rs/security/advisories/GHSA-hfpc-8r3f-gw53[WEB]
- https://github.com/aws/aws-lc/security/advisories/GHSA-jchq-39cv-q4wj[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-3338[ADVISORY]
- https://aws.amazon.com/security/security-bulletins/2026-005-AWS[WEB]
- https://github.com/aws/aws-lc-rs[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2026-0047.html[WEB]