Impact
The ca-certificates package before version ca-certificates-2021.2.50-72 on Amazon Linux 2 does not properly remove certain TrustCor root certificates from the system trust store. Because these roots remain trusted, an attacker can present a forged certificate chain that includes the lingering root, enabling the system to man‑in‑the‑middle attacks, credential theft, and the potential execution of malicious code over encrypted channels.
Affected Systems
Amazon Linux 2 systems that have the ca‑certificates package older than 2021.2.50‑72 are affected, as the issue originates from an earlier incorrect fix for CVE‑2022‑23491. The vulnerability applies only to the trust store maintained by Amazon Linux 2 and does not affect other distributions.
Risk and Exploitability
The CVSS base score of 7.5 indicates high severity. EPSS (< 1%) indicates a very low probability of exploitation, and the vulnerability. The likely attack vector involves remotely supplying a forged certificate chain that the system will accept, or locally injecting such a chain if the attacker has access to the host. Successful exploitation would grant an attacker the ability to intercept or tamper with TLS traffic intended for the affected system.
OpenCVE Enrichment