CVE-2026-3337 Details
Description
Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an unauthenticated user to potentially determine authentication tag validity via timing analysis. The impacted implementations are through the EVP CIPHER API: EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm. Customers of AWS services do not need to take action. Applications using AWS-LC should upgrade to AWS-LC version 1.69.0.
A timing side-channel vulnerability has been identified in AWS-LC, an open-source cryptographic library. This issue allows an unauthenticated user to potentially infer the validity of authentication tags during AES-CCM decryption by analyzing timing discrepancies. The vulnerability affects versions 1.21.0 prior to 1.69.0, as well as AWS-LC-FIPS-3.0.0 prior to 3.2.0. The issue arises in the EVP CIPHER API implementations of EVP_aes_128_ccm, EVP_aes_192_ccm, and EVP_aes_256_ccm.
Users of AWS-LC should upgrade to version 1.69.0 or later. For those using AWS-LC-FIPS, upgrade to version 3.2.0. Applications currently using AES-CCM with (M=4, L=2), (M=8, L=2), or (M=16, L=2) can temporarily switch to the EVP AEAD API with the corresponding Bluetooth or Matter implementations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-005-AWS/ | AMZN | Vendor Advisory |
| https://github.com/aws/aws-lc/releases/tag/v1.69.0 | AMZN | Release Notes |
| https://github.com/aws/aws-lc/security/advisories/GHSA-frmv-5gcm-jwxh | AMZN | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-208 | Observable Timing Discrepancy | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon aws-lc-fips-sys | >= 0.13.0, < 0.13.12 |
CPE
Remediation
| |
| amazon aws-lc-sys | >= 0.14.0, < 0.38.0 |
CPE
Remediation
| |
| amazon aws libcrypto | >= 1.21.0, < 1.69.0 >= 3.0.0, < 3.2.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 11, 2026 | Reanalysis | [email protected] |
| Mar 9, 2026 | Initial Analysis | [email protected] |
| Mar 2, 2026 | CVE Modified | AMZN |
| Mar 2, 2026 | New CVE Received | AMZN |