aws / aws/eks-distro

K8s Security: [kubernetes-announce] [Security Advisory] CVE-2026-3865: CSI Driver for SMB path traversal via subDir may delete unintended directories on the SMB server

Open
#4,645 0 comments 0 reactions 0 assignees View on GitHub
external kubernetes on-call security
Dominant language
Shell
Stars
1.5k
Forks
198
Avg merge
10h 46m
Merged PRs (30d)
28

Description

Go to [the Kubernetes group](https://groups.google.com/g/kubernetes-security-announce) to view the announcement.

Follow the on-call runbook to backport fixes to all supported versions.

Contributor guide

Open the contributing guide

Research direction

Start with the linked Kubernetes security announcement and the repository's on-call runbook to identify the affected CSI Driver for SMB fix and supported versions. Confirm the required backports and use the runbook's validation steps; done means the fixes are backported across all supported versions.

Written by the indexing model from the issue text.

Assessment

Domain
infrastructure, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.