Skip to content

RUSTSEC-2026-0047: PKCS7_verify Signature Validation Bypass in AWS-LC #66

@github-actions

Description

@github-actions

PKCS7_verify Signature Validation Bypass in AWS-LC

Details
Package aws-lc-sys
Version 0.34.0
URL https://aws.amazon.com/security/security-bulletins/2026-005-AWS
Date 2026-03-02
Patched versions >=0.38.0
Unaffected versions <0.24.0

Improper signature validation in PKCS7_verify() in AWS-LC allows an
unauthenticated user to bypass signature verification when processing PKCS7
objects with Authenticated Attributes.

Customers of AWS services do not need to take action. aws-lc-sys contains
code from AWS-LC. Applications using aws-lc-sys should upgrade to the most
recent release of aws-lc-sys.

There is no workaround; applications using aws-lc-sys should upgrade to the
most recent release of aws-lc-sys.

See advisory page for additional details.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions