Skip to content
AWSGHSA-h5p4-28rh-q272

Issue with parsing Certificate Common Name (CN) in s2n-tls

LowPublished Feb 14, 2023

An issue in s2n-tls results in skipping a certificate’s Common Name field validation if it exceeds 255 bytes. As a result, s2n-tls incorrectly validates a certificate that has a Common Name (CN) larger than 255 bytes, doesn’t have a Subject Alternative Name (SAN), and is signed by a trusted Certificate Authority (CA). No AWS services are affected by this issue and customers of AWS services do not need to take action. Client applications using s2n-tls should upgrade their application to the most recent release of s2n-tls. Impacted versions: All versions of s2n-tls from commit e954e6e through commit 4bd1505. Affected s2n-tls users should fetch s2n-tls commit a58b308 or later.

GitHub advisory

Affected versions

PackageAffectedFixed in
s2n-tls
Product
< v1.3.35v1.3.35
Details and references

More AWS advisories

All AWS
Advisory
Potential denial of service after connection migration
LowJul 24, 2023
Potential denial of service when receiving empty UDP packets
MediumJun 30, 2023
EKS overly permissive trust policies
Medium6.6Jun 19, 2023
Privilege Escalation Vector in CloudWatch Agent for Windows
High7.1Dec 10, 2022
Issue with configuring session ticket names in s2n-tls
MediumSep 27, 2022
Server denial-of-service by using sslv2 message format in a HelloRetryRequest handshake
LowSep 27, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.