GCP News - 2026-01-29
2026-01-29
最終更新: 2026-08-27 21:31:34 JST
GKE Security Bulletins
GCP-2026-006
- Link: https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-006
- Published: 2026-01-29 09:00:00
- Fetched: 2026-08-27 21:31:34
詳細を表示
Published: 2026-01-29
Updated: 2026-02-20
Reference: CVE-2025-154672026-02-20 Update: Added patch versions for GKE.
GKE
Updated: 2026-02-20
| Description | Severity |
|---|---|
|
Multiple security vulnerabilities have been identified in the OpenSSL library. The most significant finding is CVE-2025-15467, a critical vulnerability that might allow for remote code execution (RCE) or denial of service (DoS) attacks via network-based vectors. GKE control plane and infrastructure is not vulnerable. GKE core infrastructure, including the Kubernetes API Server and Kubelet, remains unaffected. These services use BoringCrypto (a security-hardened module derived from BoringSSL), which does not contain the vulnerable code found in the standard OpenSSL distribution. GKE Nodes: The OpenSSL library included in the GKE Node OS images (Container-Optimized OS and Ubuntu) contains the vulnerable code. While the control plane is secure, software running within your nodes or administrative tools on the host OS might be at risk. Updated GKE versions will include will the latest version of OpenSSL, which addresses the following CVEs:
What should I do?2026-02-20 Update: The following versions of GKE are updated with code to fix this vulnerability. Upgrade your GKE node pools to the following versions or later:
There is no action at this time. This security bulletin will be updated when new GKE versions are available that use the patched version of OpenSSL. |
High |
GDC (VMware)
| Description | Severity |
|---|---|
|
Multiple security vulnerabilities have been identified in the OpenSSL library. The most significant finding is CVE-2025-15467, a critical vulnerability that might allow for remote code execution (RCE) or denial of service (DoS) attacks via network-based vectors. GDC software for VMware control plane and infrastructure is not vulnerable. GDC software for VMware core infrastructure, including the Kubernetes API Server and Kubelet, remains unaffected. These services use BoringCrypto (a security-hardened module derived from BoringSSL), which does not contain the vulnerable code found in the standard OpenSSL distribution. GDC software for VMware Nodes: The OpenSSL library included in the GDC software for VMware Node OS images (Container-Optimized OS and Ubuntu) contains the vulnerable code. While the control plane is secure, software running within your nodes or administrative tools on the host OS might be at risk. Updated GDC software for VMware versions will include will the latest version of OpenSSL, which addresses the following CVEs:
What should I do?There is no action at this time. This security bulletin will be updated when new Google Distributed Cloud versions are available that use the patched version of OpenSSL. |
High |
GKE on AWS
| Description | Severity |
|---|---|
|
Multiple security vulnerabilities have been identified in the OpenSSL library. The most significant finding is CVE-2025-15467, a critical vulnerability that might allow for remote code execution (RCE) or denial of service (DoS) attacks via network-based vectors. GKE on AWS control plane and infrastructure is not vulnerable. GKE on AWS core infrastructure, including the Kubernetes API Server and Kubelet, remains unaffected. These services use BoringCrypto (a security-hardened module derived from BoringSSL), which does not contain the vulnerable code found in the standard OpenSSL distribution. GKE on AWS Nodes: The OpenSSL library included in the GKE on AWS Node OS images (Container-Optimized OS and Ubuntu) contains the vulnerable code. While the control plane is secure, software running within your nodes or administrative tools on the host OS might be at risk. Updated GKE on AWS versions will include will the latest version of OpenSSL, which addresses the following CVEs:
What should I do?There is no action at this time. This security bulletin will be updated when new GKE on AWS versions are available that use the patched version of OpenSSL. |
High |
GKE on Azure
| Description | Severity |
|---|---|
|
Multiple security vulnerabilities have been identified in the OpenSSL library. The most significant finding is CVE-2025-15467, a critical vulnerability that might allow for remote code execution (RCE) or denial of service (DoS) attacks via network-based vectors. GKE on Azure control plane and infrastructure is not vulnerable. GKE on Azure core infrastructure, including the Kubernetes API Server and Kubelet, remains unaffected. These services use BoringCrypto (a security-hardened module derived from BoringSSL), which does not contain the vulnerable code found in the standard OpenSSL distribution. GKE on Azure Nodes: The OpenSSL library included in the GKE on Azure Node OS images (Container-Optimized OS and Ubuntu) contains the vulnerable code. While the control plane is secure, software running within your nodes or administrative tools on the host OS might be at risk. Updated GKE on Azure versions will include will the latest version of OpenSSL, which addresses the following CVEs:
What should I do?There is no action at this time. This security bulletin will be updated when new GKE on Azure versions are available that use the patched version of OpenSSL. |
High |
GDC (bare metal)
| Description | Severity |
|---|---|
|
Several security issues have been discovered in OpenSSL. The most critical is CVE-2025-15467, which could be used to execute a denial of service or remote code execution attack over the internet. GDC software for bare metal is not vulnerable to this threat. GDC software for bare metal uses BoringCrypto for network facing services such as the Kubernetes apiserver and Kubelet, and BoringCrypto is not affected by this vulnerability. BoringCrypto is extracted from BoringSSL, a fork of OpenSSL focused on security hardening and performance. GDC software for bare metal does not provide a node OS. Customers are responsible for installing and maintaining a supported Linux distribution on physical hardware before installing the GKE software. What should I do?Update your Linux OS image to one that includes the latest Open SSL distribution. |
High |