CRITICAL🇵🇱 Wersja polska

CVE-2026-4428

CVSS 9.1v4.0pub. 2026-03-19upd. 2026-03-20

A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks. To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.

🤖 AI Analysis
How it works

A logic error exists in the CRL distribution point validation module that causes partitioned CRL lists to be improperly classified as out of scope and rejected. Consequently, the library treats certificates covered by such lists as unchecked for revocation instead of rejecting them. An attacker possessing a revoked certificate can exploit this error to effectively bypass the certificate status verification mechanism.

Impact

An attacker possessing a certificate that should be revoked can effectively use it for authentication or establishing encrypted connections, bypassing PKI security measures. This may lead to unauthorized access to resources protected by certificate verification mechanisms and compromise the confidentiality and integrity of data.

Mitigation & patch

AWS-LC should be updated to version 1.71.0 or later, and in case of the FIPS variant to AWS-LC-FIPS-3.3.0 or later. Details are available in the AWS security bulletin (https://aws.amazon.com/security/security-bulletins/2026-010-AWS/) and in release notes on GitHub.

Who is affected

AWS-LC before version 1.71.0 and AWS-LC-FIPS before version 3.3.0. Affects all applications and systems using these libraries for certificate validation with partitioned CRL lists.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References