OESA-2026-3689

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3689
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3689.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3689
Upstream
Published
2026-09-05T15:03:57Z
Modified
2026-09-05T15:16:37.280335424Z
Severity
  • 6.0 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
aws-sdk-cpp security update
Details

The AWS SDK for C++ provides a modern C++ (version C++ 11 or later) interface for Amazon Web Services (AWS). This package contains the S3 component.

Security Fix(es):

Missing cryptographic key commitment in the AWS SDK for C++ may allow a user with write access to the S3 bucket to introduce a new EDK that decrypts to different plaintext when the encrypted data key is stored in an "instruction file" instead of S3's metadata record.

To mitigate this issue, upgrade AWS SDK for C++ to version 1.11.712 or later(CVE-2025-14760)

An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or heap memory corruption in an application that processes crafted Base64-encoded input.

To remediate this issue, users should upgrade to version 1.11.862.(CVE-2026-19642)

An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user to crash an application that processes crafted Base64-encoded input.

To remediate this issue, users should upgrade to version 1.11.862.(CVE-2026-19643)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / aws-sdk-cpp

Package

Name
aws-sdk-cpp
Purl
pkg:rpm/openEuler/aws-sdk-cpp&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.11.327-5.oe2403sp3

Ecosystem specific

{
    "src": [
        "aws-sdk-cpp-1.11.327-5.oe2403sp3.src.rpm"
    ],
    "x86_64": [
        "aws-sdk-cpp-1.11.327-5.oe2403sp3.x86_64.rpm",
        "aws-sdk-cpp-debuginfo-1.11.327-5.oe2403sp3.x86_64.rpm",
        "aws-sdk-cpp-debugsource-1.11.327-5.oe2403sp3.x86_64.rpm",
        "aws-sdk-cpp-devel-1.11.327-5.oe2403sp3.x86_64.rpm"
    ],
    "aarch64": [
        "aws-sdk-cpp-1.11.327-5.oe2403sp3.aarch64.rpm",
        "aws-sdk-cpp-debuginfo-1.11.327-5.oe2403sp3.aarch64.rpm",
        "aws-sdk-cpp-debugsource-1.11.327-5.oe2403sp3.aarch64.rpm",
        "aws-sdk-cpp-devel-1.11.327-5.oe2403sp3.aarch64.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3689.json"