aws-samples / aws-samples/sample-code-for-a-secure-vault-using-aws-nitro-enclaves
RUSTSEC-2026-0045: Timing Side-Channel in AES-CCM Tag Verification in AWS-LC
- Dominant language
- Rust
- Stars
- 9
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
> Timing Side-Channel in AES-CCM Tag Verification in AWS-LC
| Details | |
| ------------------- | ---------------------------------------------- |
| Package | `aws-lc-sys` |
| Version | `0.35.0` |
| URL | [https://aws.amazon.com/security/security-bulletins/2026-005-AWS](https://aws.amazon.com/security/security-bulletins/2026-005-AWS) |
| Date | 2026-03-02 |
| Patched versions | `>=0.38.0` |
| Unaffected versions | `<0.14.0` |
Observable timing discrepancy in AES-CCM decryption in AWS-LC allows an
unauthenticated user to potentially determine authentication tag validity
via timing analysis.
The impacted implementations are through the EVP CIPHER API:
`EVP_aes_128_ccm`, `EVP_aes_192_ccm`, and `EVP_aes_256_ccm`.
Customers of AWS services do not need to take action. `aws-lc-sys` contains
code from AWS-LC. Applications using `aws-lc-sys` should upgrade to the most
recent release of `aws-lc-sys`.
## Workarounds
In the special cases of using AES-CCM with (M=4, L=2), (M=8, L=2), or
(M=16, L=2), applications can workaround this issue by using AES-CCM through
the EVP AEAD API using implementations `EVP_aead_aes_128_ccm_bluetooth`,
`EVP_aead_aes_128_ccm_bluetooth_8`, and `EVP_aead_aes_128_ccm_matter`
respectively.
Otherwise, there is no workaround and applications using `aws-lc-sys` should
upgrade to the most recent release.
See [advisory page](https://rustsec.org/advisories/RUSTSEC-2026-0045.html) for additional details.
Contributor guide
Research direction
Locate the project manifest or lockfile that declares aws-lc-sys and check its current version. Update the dependency to version 0.38.0 or newer, then run the project's available Rust build and tests to confirm the upgrade succeeds.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, rust
- Domain
- cryptography, security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 55/100