aws-samples / aws-samples/sample-code-for-a-secure-vault-using-aws-nitro-enclaves

RUSTSEC-2026-0045: Timing Side-Channel in AES-CCM Tag Verification in AWS-LC

Open
#280 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
9
Forks
7
PR merge metrics
No merged PRs in 30d

Description

> Timing Side-Channel in AES-CCM Tag Verification in AWS-LC

| Details | |
| ------------------- | ---------------------------------------------- |
| Package | `aws-lc-sys` |
| Version | `0.35.0` |
| URL | [https://aws.amazon.com/security/security-bulletins/2026-005-AWS](https://aws.amazon.com/security/security-bulletins/2026-005-AWS) |
| Date | 2026-03-02 |
| Patched versions | `>=0.38.0` |
| Unaffected versions | `<0.14.0` |

Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an
unauthenticated user to potentially determine authentication tag validity
via timing analysis.

The impacted implementations are through the EVP CIPHER API:
`EVP_aes_128_ccm`, `EVP_aes_192_ccm`, and `EVP_aes_256_ccm`.

Customers of AWS services do not need to take action. `aws-lc-sys` contains
code from AWS-LC. Applications using `aws-lc-sys` should upgrade to the most
recent release of `aws-lc-sys`.

## Workarounds

In the special cases of using AES-CCM with (M=4, L=2), (M=8, L=2), or
(M=16, L=2), applications can workaround this issue by using AES-CCM through
the EVP AEAD API using implementations `EVP_aead_aes_128_ccm_bluetooth`,
`EVP_aead_aes_128_ccm_bluetooth_8`, and `EVP_aead_aes_128_ccm_matter`
respectively.

Otherwise, there is no workaround and applications using `aws-lc-sys` should
upgrade to the most recent release.

See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0045.html) for additional details.

Contributor guide

Open the contributing guide

Research direction

Locate the project manifest or lockfile that declares aws-lc-sys and check its current version. Update the dependency to version 0.38.0 or newer, then run the project's available Rust build and tests to confirm the upgrade succeeds.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, rust
Domain
cryptography, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.