GCP News - 2026-04-14
2026-04-14
最終更新: 2026-08-27 21:31:34 JST
GKE Security Bulletins
GCP-2026-020
- Link: https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-020
- Published: 2026-04-14 09:00:00
- Fetched: 2026-08-27 21:31:34
詳細を表示
Published: 2026-04-14
Reference: CVE-2026-23231
GKE
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
GKE Standard clusters are impacted. GKE Autopilot clusters in the default configuration are not impacted, but might be vulnerable if you explicitly set the seccomp Clusters using GKE Sandbox aren't impacted. What should I do?The following minor versions are affected. Upgrade your Container-Optimized OS node pools to one of the following patch versions or later:
You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see Run patch versions from a newer channel. |
High |
GDC (VMware)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on AWS
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GKE on Azure
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do? |
Pending |
GDC (bare metal)
| Description | Severity |
|---|---|
|
The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes:
What should I do?There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution. |
None |