In plain language
What this advisory means
A security issue was found in the Amazon EFS CSI Driver, used by Kubernetes clusters with Amazon Elastic File System. Someone with permission to create PersistentVolumes could add extra mount instructions that the system would accept, possibly causing unexpected behavior. Users should upgrade to version 3.5.0 or later and restrict who can create PersistentVolumes to trusted administrators.
Technical explanation
How the issue affects the environment
CVE-2026-103505 is a mount option injection vulnerability in the Amazon EFS CSI Driver versions 3.1.0 and above. An attacker with PersistentVolume creation privileges can exploit the mounttargetipmap volumeAttribute by appending comma-separated values within its JSON map entries. The mount utility interprets these appended values as separate mount options, potentially leading to unintended mount configurations. This can affect the security and stability of the system mounting EFS volumes within Kubernetes clusters.
Operational impact
Why teams should care
If exploited, an attacker could influence how file systems are mounted in Kubernetes clusters using Amazon EFS, possibly leading to unauthorized access, privilege escalation, or disruption of workloads that rely on correctly mounted storage. This puts business applications running on affected clusters at risk until the vulnerability is mitigated.
Immediate action
Upgrade the Amazon EFS CSI Driver to version 3.5.0 or later. Also, ensure any derivative or forked code is updated accordingly to include the fix.
Affected and fixed releases
Temporary risk reduction
Use Kubernetes Role-Based Access Control (RBAC) to restrict PersistentVolume and StorageClass creation privileges to trusted cluster administrators only, preventing untrusted users from injecting arbitrary mount options.
Evidence and validation checklist
- AWS Security Bulletin 2026-120-AWS published 10/01/2026
- CVE-2026-103505 description from AWS
- Version and remediation information from AWS bulletin
- Kubernetes RBAC recommended as an access control workaround
Authoritative reference
AWS Security Bulletins
QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.
