GCP News - 2025-11-10
2025-11-10
最終更新: 2026-08-27 21:31:34 JST
GKE Security Bulletins
GCP-2025-066
- Link: https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2025-066
- Published: 2025-11-10 09:00:00
- Fetched: 2026-08-27 21:31:34
詳細を表示
Published: 2025-11-10
Updated: 2025-11-27
Reference: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881
2025-11-27 Update: Added patch versions for GKE and GDC (bare metal).
GKE
Updated: 2025-11-27
| Description | Severity |
|---|---|
|
Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities. These vulnerabilities affect GKE Standard clusters running either Container-Optimized OS (COS) or Ubuntu node images, as well as Autopilot clusters. Node pools using GKE Sandbox are not affected and Windows node pools are not affected. What should I do?2025-11-27 Update: The following versions of GKE are updated with code to fix these vulnerabilities on Container-Optimized OS. Upgrade your GKE node pools to the following versions or later:
The following GKE versions have been updated with code to fix these vulnerabilities on Ubuntu. Upgrade your GKE node pools to the following versions or later:
You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel. GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available. |
High |
GDC (VMware)
| Description | Severity |
|---|---|
|
Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities. What should I do? GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available. |
High |
GKE on AWS
| Description | Severity |
|---|---|
|
Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities. What should I do? GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available. |
High |
GKE on Azure
| Description | Severity |
|---|---|
|
Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities. What should I do? GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available. |
High |
GDC (bare metal)
Updated: 2025-11-27
| Description | Severity |
|---|---|
|
Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities. What should I do?2025-11-27 Update: The following versions of GDC (bare metal) are updated with code to fix this vulnerability. Upgrade your GDC (bare metal) clusters to these versions or later:
GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available. |
High |