AWS res: RES 2026.09 release notes list multiple security fixes
Summary
Adds the September 2026 (2026.09) release notes documenting security fixes: arbitrary file deletion as root via FileBrowser DeleteFiles API, symlink-following in the ssh_keygen PAM module, admin impersonation via Cognito username truncation, GetModuleSettings API key exposure, service-token scoping on BatchCreateSession and a session-limit bypass, subnet ID validation, and enforcement of disabled-group/project restrictions on VDI creation.
Security assessment
The diff explicitly enumerates fixed vulnerabilities and hardening: root-level arbitrary file deletion, symlink-following privilege escalation, admin impersonation, over-broad API data exposure, missing service-token scoping/authorization bypass, and unvalidated subnet IDs — all concrete security defects addressed in this release.
Evidence
+ * Fixed an arbitrary file deletion vulnerability (running as root) via the FileBrowser DeleteFiles API.
Diff
diff --git a/res/latest/ug/revisions.md b/res/latest/ug/revisions.md index f7d6e8089..f788a837a 100644 --- a//res/latest/ug/revisions.md +++ b//res/latest/ug/revisions.md @@ -6,0 +7,2 @@ +End of development notice: AWS is discontinuing development of Research and Engineering Studio on AWS (RES). 2026.09 is the final release, supported through September 30, 2027. RES remains open source and keeps running in your account. For more information, see [RES end of support](./res-end-of-support.html). + @@ -12,0 +15,22 @@ Date | Change +September 2026 | + + * Release version 2026.09 Security fixes + * Fixed an arbitrary file deletion vulnerability (running as root) via the FileBrowser DeleteFiles API. + * Hardened the ssh_keygen PAM module against symlink-following during ownership changes. + * Prevented admin impersonation caused by Cognito username truncation. + * Restricted the GetModuleSettings API to return only the keys required for non-admin users. + * Enforced service-token scoping on the BatchCreateSession API and closed a session-limit bypass. + * Added server-side validation of user-provided subnet IDs against the allowed subnet list. + * Fixed disabled-group and disabled-project restrictions not being enforced on VDI creation. +Enhancements + * Added a smart retry mechanism that automatically retries VDI launches on transient instance-capacity failures, with corresponding web portal updates. + * Allow users to set custom schedules when creating a session. + * Allow users to override and add custom RES tags. +Changes + * Completed migration of the VDC controller from a dedicated EC2 infrastructure host to serverless Lambda-based session management. + * Session creation and deletion now launch and terminate VDI hosts directly via EC2 Fleets, and legacy controller message handlers, queues, and APIs have been removed. + * Session creation now defaults to CONSOLE, and the session type dropdown has been removed. +Bug fixes + * Fixed VDI launch failures when project tags were configured. + +