A logic error in CRL distribution point validation in AWS-LC before 1.71.0 causes partitioned CRLs to be incorrectly rejected as out of scope, which allows a revoked certificate to bypass certificate revocation checks. To remediate this issue, users should upgrade to AWS-LC 1.71.0 or AWS-LC-FIPS-3.3.0.
A logic error exists in the CRL distribution point validation module that causes partitioned CRL lists to be improperly classified as out of scope and rejected. Consequently, the library treats certificates covered by such lists as unchecked for revocation instead of rejecting them. An attacker possessing a revoked certificate can exploit this error to effectively bypass the certificate status verification mechanism.
An attacker possessing a certificate that should be revoked can effectively use it for authentication or establishing encrypted connections, bypassing PKI security measures. This may lead to unauthorized access to resources protected by certificate verification mechanisms and compromise the confidentiality and integrity of data.
AWS-LC should be updated to version 1.71.0 or later, and in case of the FIPS variant to AWS-LC-FIPS-3.3.0 or later. Details are available in the AWS security bulletin (https://aws.amazon.com/security/security-bulletins/2026-010-AWS/) and in release notes on GitHub.
AWS-LC before version 1.71.0 and AWS-LC-FIPS before version 3.3.0. Affects all applications and systems using these libraries for certificate validation with partitioned CRL lists.
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X