CVE-2026-3337
EUVD-2026-926502.03.2026, 22:16
Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| amazon | aws-lc-fips-sys | 0.13.0 ≤ 𝑥 < 0.13.12 |
| amazon | aws-lc-sys | 0.14.0 ≤ 𝑥 < 0.38.0 |
| amazon | aws_libcrypto | 1.21.0 ≤ 𝑥 < 1.69.0 |
| amazon | aws_libcrypto | 3.0.0 ≤ 𝑥 < 3.2.0 |
𝑥
= Vulnerable software versions