2026-010-AWS
CVE-2026-4428: Issues with AWS-LC - CRL Distribution Point Scope Check Logic Error
🔗 CVE IDs covered (1)
📋 Description
Bulletin ID: 2026-010-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/19 13:30 PM PDT
Description:
AWS-LC is a general-purpose cryptographic library maintained by AWS. We identified CVE-2026-4428 affecting X.509 certificate verification.
A logic error in the CRL (Certificate Revocation List) distribution point matching in AWS-LC allows a revoked certificate to bypass revocation checks during certificate validation, when the application enables CRL checking and uses partitioned CRLs with Issuing Distribution Point (IDP) extensions.
Applications that do not enable CRL checking (X509_V_FLAG_CRL_CHECK) are not affected. Applications using complete (non-partitioned) CRLs without IDP extensions are also not affected.
Impacted versions: - CRL Distribution Point Scope Check Logic Error in AWS-LC >= v1.24.0, - CRL Distribution Point Scope Check Logic Error in AWS-LC-FIPS >= AWS-LC-FIPS-3.0.0, - CRL Distribution Point Scope Check Logic Error in aws-lc-sys >= v0.15.0, - CRL Distribution Point Scope Check Logic Error in aws-lc-fips-sys >= v0.13.0,
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.