AWS res: Release notes add June 2026 security fixes and enhancements
Summary
Adds the 2026.06 release entry covering fixed vulnerabilities (symlink handling in the File System API allowing arbitrary file read, Linux kernel local privilege escalation addressed by default AMI updates), plus feature/enhancement, change, and bug-fix notes; also adds an Archive notice section.
Security assessment
The changed line explicitly discloses a fixed vulnerability: authenticated users could abuse symlink handling in the File System API on the cluster manager host to read arbitrary files (a symlink/path-traversal class flaw enabling unauthorized file disclosure). A second bullet notes default AMIs were updated to resolve a Linux kernel local privilege escalation vulnerability. Both are concrete, fixed security defects, so this is high severity.
Evidence
* Fixed a security vulnerability where an authenticated user could exploit symlink handling in the File System API on the cluster manager host to read arbitrary files.
Diff
diff --git a/res/archive/release-minus-1/ug/revisions.md b/res/archive/release-minus-1/ug/revisions.md index 2ada04a5b..098c1fd9a 100644 --- a//res/archive/release-minus-1/ug/revisions.md +++ b//res/archive/release-minus-1/ug/revisions.md @@ -12,0 +13,18 @@ Date | Change +June 2026 | + + * Release version 2026.06 Security fixes + * Fixed a security vulnerability where an authenticated user could exploit symlink handling in the File System API on the cluster manager host to read arbitrary files. +Enhancements + * Replaced DCV broker infrastructure host with serverless Lambda-based session management, reducing infrastructure overhead and improving scalability. + * Included QUIC, default schedule, and other cluster settings in snapshot restore functionality. +Changes + * Continued migration of VDC-related APIs from the VDC infra host to the backend Lambda. +Bug fixes + * Fixed "Create Software Stack from Session" workflow failing due to stale AD credentials, missing IAM permissions, and incompatible EC2Launch version on Windows. + * Fixed Ubuntu VDI login failure caused by SSSD configuration parsing error with special characters in home directory paths. + * Fixed list project owners and members in the user drop-down when sharing a Virtual Desktop. + * Fixed VDI login failures on RHEL8, RHEL9, Ubuntu 22.04, and Ubuntu 24.04 caused by amazon-efs-utils build incompatibility preventing EFS /home directory mounting. + * Fixed IAM policies not appearing in "add policies" dropdown when account has more than 1000 policies. + * Updated default AMIs across all supported OS types and regions, resolving Linux kernel local privilege escalation vulnerability. + + @@ -185,0 +204,2 @@ Notices +Archive +