CVE-2026-4428

EUVD-2026-13237
A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows  a revoked certificate to bypass certificate revocation checks.

To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.4 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
amazon-efs-utils
Amazon Linux 2
0:3.0.0-4.amzn2
fixed
Amazon Linux 2023
0:3.0.0-4.amzn2023
fixed
mount-s3
Amazon Linux 2023
0:1.22.3-1.amzn2023
fixed
mount-s3-debuginfo
Amazon Linux 2023
0:1.22.3-1.amzn2023
fixed
mount-s3-debugsource
Amazon Linux 2023
0:1.22.3-1.amzn2023
fixed