TrustCor Root Certificates Vulnerability in Amazon Linux 2
CVE-2023-32803

Currently unrated

Key Information:

Vendor

Amazon

Vendor
CVE Published:
14 September 2026

What is CVE-2023-32803?

The ca-certificates package in Amazon Linux 2 prior to version 2021.2.50-72 fails to adequately remove specific TrustCor root certificates from its root store. This oversight arises from an incorrect remediation related to a previous vulnerability. The persistence of these certificates poses a risk, as they might facilitate unauthorized access or misalign security protocols within systems relying on the trust worthiness of the root store.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.