Description
The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Trust of Compromised Root Certificates
Action: Immediate Patch
AI Analysis

Impact

The ca-certificates package before version ca-certificates-2021.2.50-72 on Amazon Linux 2 does not properly remove certain TrustCor root certificates from the system trust store. Because these roots remain trusted, an attacker can present a forged certificate chain that includes the lingering root, enabling the system to man‑in‑the‑middle attacks, credential theft, and the potential execution of malicious code over encrypted channels.

Affected Systems

Amazon Linux 2 systems that have the ca‑certificates package older than 2021.2.50‑72 are affected, as the issue originates from an earlier incorrect fix for CVE‑2022‑23491. The vulnerability applies only to the trust store maintained by Amazon Linux 2 and does not affect other distributions.

Risk and Exploitability

The CVSS base score of 7.5 indicates high severity. EPSS (< 1%) indicates a very low probability of exploitation, and the vulnerability. The likely attack vector involves remotely supplying a forged certificate chain that the system will accept, or locally injecting such a chain if the attacker has access to the host. Successful exploitation would grant an attacker the ability to intercept or tamper with TLS traffic intended for the affected system.

Generated by OpenCVE AI on September 15, 2026 at 16:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the ca-certificates package to version 2021.2.50‑72 or later on Amazon Linux 2‑ca‑trust after the upgrade to ensure all stale roots are removed.
  • If an immediate upgrade is not possible, delete any remaining TrustCor root certificates from the root store (for example, remove the corresponding .pem files from /etc/pki/ca-trust/source/anchors/) and regenerate the trust database with update‑ca‑trust.
  • Apply any additional security updates for Amazon Linux 2 that address TLS or CA handling to further mitigate related risks.

Generated by OpenCVE AI on September 15, 2026 at 16:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Amazon
Amazon ca-certificates
Vendors & Products Amazon
Amazon ca-certificates

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title ca-certificates: ca-certificates: Failure to remove TrustCor root certificates
Weaknesses CWE-459
References
Metrics threat_severity

None

threat_severity

Important


Mon, 14 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-669
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}


Mon, 14 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Description The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store. NOTE: this issue exists because of an incorrect fix for CVE-2022-23491.
References

Subscriptions

Amazon Ca-certificates
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T15:09:03.439Z

Reserved: 2023-05-15T00:00:00.000Z

Link: CVE-2023-32803

cve-icon Vulnrichment

Updated: 2026-09-14T15:08:59.424Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T05:16:57.290

Modified: 2026-09-22T19:56:19.073

Link: CVE-2023-32803

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-14T00:00:00Z

Links: CVE-2023-32803 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T19:47:00Z

Weaknesses
  • CWE-459

    Incomplete Cleanup

  • CWE-669

    Incorrect Resource Transfer Between Spheres