GCP News - 2025-12-02

2025-12-02
最終更新: 2026-08-27 21:31:34 JST

GKE Security Bulletins

GCP-2025-071

詳細を表示

Published: 2025-12-02
Updated: 2026-03-25
Reference: CVE-2025-40019

2026-03-25 Update: Added patch versions for Ubuntu nodes with GKE.

2025-12-11 Update: Added patch versions and a severity rating for GDC (VMware).

GKE

Updated: 2026-03-25

Description Severity

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:

  • CVE-2025-40019

GKE Standard and Autopilot clusters are impacted.

Clusters using GKE Sandbox aren't impacted.

What should I do?

2026-03-25 Update: The following versions of GKE are updated with code to fix this vulnerability on Ubuntu. Upgrade your Ubuntu node pools to the following versions or later:

  • 1.35.1-gke.1396000
  • 1.34.4-gke.1047000
  • 1.33.8-gke.1026000
  • 1.32.12-gke.1026000
  • 1.31.14-gke.1476000
  • 1.30.14-gke.2117000

The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later:

  • 1.28.15-gke.2966000
  • 1.32.9-gke.1330000
  • 1.33.5-gke.1350000
  • 1.29.15-gke.2236000
  • 1.31.13-gke.1231000
  • 1.30.14-gke.1525000
  • 1.34.1-gke.2541000

You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel.

High

GDC (VMware)

Updated: 2025-12-11

Description Severity

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:

  • CVE-2025-40019

What should I do?

The following versions of GDC (VMware) are updated with code to fix this vulnerability. Upgrade your GDC (VMware) clusters to the following versions or later:

  • 1.31.1100-gke.40

High

GKE on AWS

Description Severity

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:

  • CVE-2025-40019

What should I do?

Pending

GKE on Azure

Description Severity

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:

  • CVE-2025-40019

What should I do?

Pending

GDC (bare metal)

Description Severity

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:

  • CVE-2025-40019

What should I do?

There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution.

None

GCP-2025-070

詳細を表示

Published: 2025-12-02
Updated: 2026-03-25
Reference: CVE-2025-40018

2026-03-25 Update: Added patch versions for Ubuntu nodes with GKE.

2025-12-11 Update: Added patch versions and a severity rating for GDC (VMware).

GKE

Updated: 2026-03-25

Description Severity

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:

  • CVE-2025-40018

GKE Standard clusters are impacted. GKE Autopilot clusters in the default configuration are not impacted, but might be vulnerable if you explicitly set the seccomp Unconfined profile or allow CAP_NET_ADMIN.

Clusters using GKE Sandbox aren't impacted.

What should I do?

2026-03-25 Update: The following versions of GKE are updated with code to fix this vulnerability on Ubuntu. Upgrade your Ubuntu node pools to the following versions or later:

  • 1.35.1-gke.1396000
  • 1.34.4-gke.1047000
  • 1.33.8-gke.1026000
  • 1.32.12-gke.1026000
  • 1.31.14-gke.1336000
  • 1.30.14-gke.1991000

The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later:

  • 1.32.9-gke.1330000
  • 1.29.15-gke.2236000
  • 1.30.14-gke.1525000
  • 1.31.13-gke.1231000
  • 1.34.1-gke.2541000
  • 1.28.15-gke.2966000
  • 1.33.5-gke.1350000

You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel.

High

GDC (VMware)

Updated: 2025-12-11

Description Severity

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:

  • CVE-2025-40018

What should I do?

The following versions of GDC (VMware) are updated with code to fix this vulnerability. Upgrade your GDC (VMware) clusters to the following versions or later:

  • 1.31.1100-gke.40

High

GKE on AWS

Description Severity

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:

  • CVE-2025-40018

What should I do?

Pending

GKE on Azure

Description Severity

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:

  • CVE-2025-40018

What should I do?

Pending

GDC (bare metal)

Description Severity

The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:

  • CVE-2025-40018

What should I do?

There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution.

None