GCP News - 2026-06-18
2026-06-18
最終更新: 2026-08-27 21:31:34 JST
GKE Security Bulletins
GCP-2026-037
- Link: https://docs.cloud.google.com/kubernetes-engine/security-bulletins#gcp-2026-037
- Published: 2026-06-18 09:00:00
- Fetched: 2026-08-27 21:31:34
詳細を表示
Published: 2026-06-18
Updated: 2026-06-20
Reference: CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, CVE-2026-47262
2026-06-20 Update: Added GKE patch versions containing the fixes for Container-Optimized OS node images for minor versions 1.35 and 1.36. Patches for Ubuntu node images are still pending and in progress.
2026-06-19 Update: Added GKE patch versions containing the fixes for Container-Optimized OS node images for minor versions from 1.30 to 1.34. Patches for Ubuntu node images and for minor version 1.35 and 1.36 for Container-Optimized OS node images are in progress.
| Description | Severity |
|---|---|
|
The following vulnerabilities have been discovered in containerd (the GKE container runtime). These vulnerabilities allow attackers with permissions to create Pods to bypass Kubernetes security boundaries and perform host compromise, cache poisoning, and denial of service. While these vulnerabilities are critical in the context of containerd, the requirement to have cluster privileges to create Pods to exploit them means they are considered High according to GKE vulnerability classification.
These vulnerabilities affect all GKE configurations using Container-Optimized OS and Ubuntu node images, including GKE Standard and GKE Autopilot clusters. What should I do?2026-06-20 Update: The following GKE patch versions contain the fixes for Container-Optimized OS node images for minor versions from 1.30 to 1.36. Upgrade your Container-Optimized OS node pools to the following versions or later:
Patches for Ubuntu node images are in progress. Until patch versions are available, use the following mitigation guidelines:
|
High |