AWS‑LC Crypto Flaws Enable PKCS7 Bypass and Timing Leak

AWS published an advisory for three vulnerabilities in the AWS‑LC cryptographic library. Unauthenticated actors can bypass PKCS7 signature and certificate‑chain validation on certain PKCS7 objects. A separate timing side‑channel can disclose AES‑CCM authentication tag validity on affected builds.

Part of the PlainSec briefing for 2026-03-03

Sources