GCP News - 2025-11-10

2025-11-10
最終更新: 2026-08-27 21:31:34 JST

GKE Security Bulletins

GCP-2025-066

詳細を表示

Published: 2025-11-10
Updated: 2025-11-27
Reference: CVE-2025-31133, CVE-2025-52565, CVE-2025-52881

2025-11-27 Update: Added patch versions for GKE and GDC (bare metal).

GKE

Updated: 2025-11-27

Description Severity

Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities.

These vulnerabilities affect GKE Standard clusters running either Container-Optimized OS (COS) or Ubuntu node images, as well as Autopilot clusters. Node pools using GKE Sandbox are not affected and Windows node pools are not affected.

What should I do?

2025-11-27 Update: The following versions of GKE are updated with code to fix these vulnerabilities on Container-Optimized OS. Upgrade your GKE node pools to the following versions or later:

  • 1.34.1-gke.3355000
  • 1.33.5-gke.1791000
  • 1.32.9-gke.1548000
  • 1.31.13-gke.1454000
  • 1.30.14-gke.1719000
  • 1.29.15-gke.2467000
  • 1.28.15-gke.3163000

The following GKE versions have been updated with code to fix these vulnerabilities on Ubuntu. Upgrade your GKE node pools to the following versions or later:

  • 1.33.5-gke.1791000

You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel.


GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available.

High

GDC (VMware)

Description Severity

Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities.

What should I do?

GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available.

High

GKE on AWS

Description Severity

Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities.

What should I do?

GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available.

High

GKE on Azure

Description Severity

Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities.

What should I do?

GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available.

High

GDC (bare metal)

Updated: 2025-11-27

Description Severity

Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities.

What should I do?

2025-11-27 Update: The following versions of GDC (bare metal) are updated with code to fix this vulnerability. Upgrade your GDC (bare metal) clusters to these versions or later:

  • 1.31.1000-gke.44

GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available.

High