Mount Option Injection in Amazon EFS CSI Driver
UnratedCVE-2026-6437 · Published Apr 17, 2026 · updated Sep 25, 2026
Bulletin ID: 2026-016-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/17/2026 11:15 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-6437 , where an actor with PersistentVolume creation privileges can inject arbitrary mount options via two unsanitized fields: the Access Point ID in volumeHandle and the mounttargetip volumeAttribute. In both cases, appending comma-separated values causes the mount utility to parse them as separate mount options. Impacted versions: EFS CSI Driver Resolution: This issue has been addressed in EFS CSI Driver version v3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Restrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. References: CVE-2026-6437 GHSA-mph4-q2vm-w2pw Acknowledgement: We would like to thank Shaul Ben-Hai from Sentinel One for collaborating on...
Affected versions
Details and references
Bulletin ID: 2026-016-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/17/2026 11:15 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-6437 , where an actor with PersistentVolume creation privileges can inject arbitrary mount options via two unsanitized fields: the Access Point ID in volumeHandle and the mounttargetip volumeAttribute. In both cases, appending comma-separated values causes the mount utility to parse them as separate mount options. Impacted versions: EFS CSI Driver Resolution: This issue has been addressed in EFS CSI Driver version v3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Restrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. References: CVE-2026-6437 GHSA-mph4-q2vm-w2pw Acknowledgement: We would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-016-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-6437 - Mount Option Injection in Amazon EFS CSI Driver Bulletin ID: 2026-016-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/17/2026 11:15 AM PDT Description: The Amazon EFS CSI Driver is a Container Storage Interface driver that allows Kubernetes clusters to use Amazon Elastic File System. We identified CVE-2026-6437 , where an actor with PersistentVolume creation privileges can inject arbitrary mount options via two unsanitized fields: the Access Point ID in volumeHandle and the mounttargetip volumeAttribute. In both cases, appending comma-separated values causes the mount utility to parse them as separate mount options. Impacted versions: EFS CSI Driver Resolution: This issue has been addressed in EFS CSI Driver version v3.0.1 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Restrict PersistentVolume and StorageClass creation to cluster administrators using Kubernetes RBAC, preventing untrusted users from supplying arbitrary field values. References: CVE-2026-6437 GHSA-mph4-q2vm-w2pw Acknowledgement: We would like to thank Shaul Ben-Hai from Sentinel One for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veter
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 29 | Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues | Unrated | No fix yet |
| Apr 27 | Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS | Unrated | No fix yet |
| Apr 24 | Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912 | Unrated | No fix yet |
| Apr 20 | Key commitment policy bypass via shared key cache in AWS Encryption SDK for Python | Unrated | No fix yet |
| Apr 7 | Out-of-bounds Write in Firecracker virtio-pci Transport | Unrated | No fix yet |
| Apr 6 | Issues with AWS Research and Engineering Studio (RES) | Unrated | No fix yet |