Network policy agent: return errors from eBPF map updates
Fixed in: AWS network policy agent v1.3.7 contains PR #562
details
- Finding IDs
- F-NPA-FAILOPEN-001
- Status
- fixed publicly
- Fixed in
- AWS network policy agent v1.3.7 contains PR #562
- Recorded credit
- Public fix author: parlakisik. Public 1seal credit and a causal link to our report are not established.
- Note
- Merged 2026-05-21. The patch returns joined errors from policy and pod-state map updates instead of hiding failed writes and adds caller-facing regression tests. This matches the reported error-propagation defect and is separate from PR #563. The earlier reduced model did not demonstrate traffic blocking after a failure. Complete network protection after partial update failure is not established by this record; no separate CVE is assigned.
F-NPA-FAILOPEN-001: Input / state handling. A failed policy-map update must return an error so its caller does not treat incomplete enforcement as success. Reviewed 7 Oct 2026. Mechanism assessed by 1seal.
Mechanism source for F-NPA-FAILOPEN-001
Security area (1seal assessment): Authorization. A failed policy-map update must return an error so its caller does not treat incomplete enforcement as success. Reviewed 7 Oct 2026.