GCP News - 2026-07-28

2026-07-28
最終更新: 2026-08-27 21:31:25 JST

Google Cloud Release Notes

July 28, 2026

詳細を表示

AlloyDB for PostgreSQL

Feature

IAM group authentication for AlloyDB is available in Preview for new clusters running PostgreSQL 15 and later. This feature simplifies database user management by allowing access management at the group level, where group members inherit database roles and permissions. To use this feature, enable the alloydb.iam_authentication and alloydb.iam_group_authentication database flags.

For more information, see IAM group authentication and Manage IAM authentication.

Compute Engine

Feature

Hyperdisk Balanced volumes on C4D instances have increased maximum throughput limits for these machine types:

  • c4d-*-96: 3,125 MiB/s (up from 2,800 MiB/s).
  • c4d-*-192: 6,250 MiB/s (up from 4,800 MiB/s).
  • c4d-*-384: 12,500 MiB/s (up from 10,000 MiB/s).

For detailed performance limits, see Hyperdisk Balanced performance limits when attached to an instance.

Confidential VM

Issue

Starting August 2026, Confidential VM instances using AMD SEV-SNP might have longer boot times and performance changes due to a guest kernel migration and security updates. This issue is expected to be resolved by November 2026. Confidential VM instances using AMD SEV or Intel TDX aren't affected.

Container Optimized OS

Change

cos-129-19506-299-60

Kernel Docker Containerd GPU Drivers
COS-6.12.94 v27.5.1 v2.2.5 See List

Fixed

Updated udev rule for protected_stateful_partition

Fixed

Upgraded app-admin/fluent-bit to v4.2.7.

Security

Fixed CVE-2026-29111 in sys-apps/systemd

Security

Fixed CVE-2026-3644 in dev-lang/python

Security

Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.

Security

Fixed CVE-2026-53381 in the Linux kernel.

Security

Fixed CVE-2026-53385 in the Linux kernel.

Security

Fixed CVE-2026-53388 in the Linux kernel.

Security

Fixed CVE-2026-53391 in the Linux kernel.

Security

Fixed CVE-2026-53392 in the Linux kernel.

Security

Fixed CVE-2026-53393 in the Linux kernel.

Security

Fixed CVE-2026-53394 in the Linux kernel.

Security

Fixed CVE-2026-53397 in the Linux kernel.

Security

Fixed CVE-2026-53398 in the Linux kernel.

Security

Fixed CVE-2026-53400 in the Linux kernel.

Security

Fixed CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and CVE-2026-60002 in openssh.

Security

Fixed CVE-2026-6019 in dev-lang/python

Security

Fixed CVE-2026-63795 in the Linux kernel.

Security

Fixed CVE-2026-63800 in the Linux kernel.

Security

Fixed CVE-2026-63802 in the Linux kernel.

Security

Fixed CVE-2026-63806 in the Linux kernel.

Security

Fixed CVE-2026-63807 in the Linux kernel.

Security

Fixed CVE-2026-63809 in the Linux kernel.

Security

Fixed CVE-2026-63810 in the Linux kernel.

Security

Fixed CVE-2026-63823 in the Linux kernel.

Security

Fixed CVE-2026-63824 in the Linux kernel.

Security

Fixed CVE-2026-63827 in the Linux kernel.

Security

Fixed CVE-2026-63828 in the Linux kernel.

Security

Fixed CVE-2026-63829 in the Linux kernel.

Security

Fixed CVE-2026-63830 in the Linux kernel.

Security

Fixed CVE-2026-63833 in the Linux kernel.

Security

Fixed CVE-2026-64187 in the Linux kernel.

Security

Fixed CVE-2026-64189 in the Linux kernel.

Change

cos-125-19216-532-42

Kernel Docker Containerd GPU Drivers
COS-6.12.94 v27.5.1 v2.1.9 See List

Fixed

Fixed an important bug for xfs file system users.

Fixed

Updated udev rule for protected_stateful_partition

Security

Fixed CVE-2026-29111 in sys-apps/systemd

Security

Fixed CVE-2026-3644 in dev-lang/python

Security

Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.

Security

Fixed CVE-2026-53381 in the Linux kernel.

Security

Fixed CVE-2026-53385 in the Linux kernel.

Security

Fixed CVE-2026-53388 in the Linux kernel.

Security

Fixed CVE-2026-53391 in the Linux kernel.

Security

Fixed CVE-2026-53392 in the Linux kernel.

Security

Fixed CVE-2026-53393 in the Linux kernel.

Security

Fixed CVE-2026-53394 in the Linux kernel.

Security

Fixed CVE-2026-53397 in the Linux kernel.

Security

Fixed CVE-2026-53398 in the Linux kernel.

Security

Fixed CVE-2026-53400 in the Linux kernel.

Security

Fixed CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and CVE-2026-60002 in openssh.

Security

Fixed CVE-2026-6019 in dev-lang/python

Security

Fixed CVE-2026-63795 in the Linux kernel.

Security

Fixed CVE-2026-63800 in the Linux kernel.

Security

Fixed CVE-2026-63802 in the Linux kernel.

Security

Fixed CVE-2026-63806 in the Linux kernel.

Security

Fixed CVE-2026-63807 in the Linux kernel.

Security

Fixed CVE-2026-63809 in the Linux kernel.

Security

Fixed CVE-2026-63810 in the Linux kernel.

Security

Fixed CVE-2026-63823 in the Linux kernel.

Security

Fixed CVE-2026-63824 in the Linux kernel.

Security

Fixed CVE-2026-63827 in the Linux kernel.

Security

Fixed CVE-2026-63828 in the Linux kernel.

Security

Fixed CVE-2026-63829 in the Linux kernel.

Security

Fixed CVE-2026-63830 in the Linux kernel.

Security

Fixed CVE-2026-63833 in the Linux kernel.

Security

Fixed CVE-2026-64187 in the Linux kernel.

Security

Fixed CVE-2026-64189 in the Linux kernel.

Change

cos-117-18613-675-28

Kernel Docker Containerd GPU Drivers
COS-6.6.143 v24.0.9 v1.7.34 See List

Fixed

Upgraded net-fs/cifs-utils to v7.7, Upgraded sys-libs/talloc to v2.4.4-r1.

Security

Fixed CVE-2026-29111 in sys-apps/systemd

Security

Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.

Security

Fixed CVE-2026-53381 in the Linux kernel.

Security

Fixed CVE-2026-53385 in the Linux kernel.

Security

Fixed CVE-2026-53388 in the Linux kernel.

Security

Fixed CVE-2026-53391 in the Linux kernel.

Security

Fixed CVE-2026-53397 in the Linux kernel.

Security

Fixed CVE-2026-53398 in the Linux kernel.

Security

Fixed CVE-2026-6019 in dev-lang/python

Security

Fixed CVE-2026-63794 in the Linux kernel.

Security

Fixed CVE-2026-63795 in the Linux kernel.

Security

Fixed CVE-2026-63800 in the Linux kernel.

Security

Fixed CVE-2026-63802 in the Linux kernel.

Security

Fixed CVE-2026-63807 in the Linux kernel.

Security

Fixed CVE-2026-63809 in the Linux kernel.

Security

Fixed CVE-2026-63823 in the Linux kernel.

Security

Fixed CVE-2026-63824 in the Linux kernel.

Security

Fixed CVE-2026-63827 in the Linux kernel.

Security

Fixed CVE-2026-63828 in the Linux kernel.

Security

Fixed CVE-2026-63830 in the Linux kernel.

Gemini Enterprise

Feature

Gemini Enterprise: Microsoft Teams federated data store is generally available

The Microsoft Teams federated data store is generally available (GA) in Gemini Enterprise. Connect Microsoft Teams to query channels, chats, teams, and messages, and execute supported actions directly from the assistant.

For more information, see Connect Microsoft Teams.

Google Kubernetes Engine

Feature

GKE now supports opting out of the default kubernetes.io/arch=arm64:NoSchedule taint on Arm nodes in Standard node pools and in custom ComputeClasses. To opt out of the default taint, set the --node-architecture-taint-behavior gcloud CLI flag to NONE for a node pool or set the taintConfig.architectureTaintBehavior field to NONE for a ComputeClass. By configuring this behavior, you allow workloads that lack explicit Arm tolerations to be scheduled on Arm-based machine families (such as N4A and C4A). This is useful for running multi-architecture workloads or simplifying scheduling in mixed-mode clusters. For more information, see Configure the default Arm architecture taint.

Feature

GKE Gateway and Inference Gateway now support Cross-Origin Resource Sharing (CORS). You can configure a CORS filter directly on an HTTPRoute resource by using the portable syntax standardized by Gateway API. This feature is available in Preview in GKE version 1.35 and later for the following GatewayClasses:

  • gke-l7-rilb
  • gke-l7-regional-external-managed
  • gke-l7-global-external-managed

For more information, see Configure Cross-Origin Resource Sharing.

Google SecOps

Feature

[Spotlight Feature] Data RBAC for first-party (1P) cases and alerts

Availability This feature is now available in public preview for all regions.

Google SecOps now supports data role-based access control (Data RBAC) for first-party (1P) SOAR cases and alerts. This feature automatically applies SIEM data access scopes to alerts and cases ingested using the Chronicle connector, ensuring analysts only see data they are authorized to access.

For more information, see the Release Note entry for July 6th.

Managed Service for Apache Spark

Announcement

Starting with Managed Service for Apache Spark image version 3.0, clusters that are created without a specified machine type for a node are created with a Flex VM configuration for the node.

Security Command Center

Feature

Version 1.2.0 of the Google SCC ITSM app and version 1.3.0 of the Google SCC SIR app have been released.

To reflect this update, the ServiceNow integration guide is updated with the following changes:

  • Added support for ServiceNow Yokohama, Zurich, and Australia versions.
  • Added the following features:

    • Mute and unmute findings
    • Create mute rules
    • Create Configuration Item (CI) lookup rules
    • View the action log
  • Updated setup instructions for Java KeyStore certificates.

  • Added additional troubleshooting steps for maximum execution time exceeded errors, data collection issues, and ECC Queue timeout errors.

For more information, see Sending Security Command Center data to ServiceNow.

Spanner

Feature

Spanner supports creating tables without defining primary keys. When you create a table without a primary key, Spanner creates a hidden rowid column that serves as the primary key. For more information, see Create a table without defining a primary key.