Container-Optimized OS Release Notes: Milestone 117

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

November 17, 2025

Change

cos-117-18613-439-28

Kernel Docker Containerd GPU Drivers
COS-6.6.111 v24.0.9 v1.7.28 See List
Change

Updated app-containers/runc to v1.2.8.

Feature

Added support for the Lustre 2.14.0_p224 drivers.

Fixed

Backported an upstream commit to fix high CPU usage when trying to find suitable blocks in ext4 fs.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811751 -> 811818

November 11, 2025

Change

cos-117-18613-439-22

Kernel Docker Containerd GPU Drivers
COS-6.6.111 v24.0.9 v1.7.28 See List
Security

Fixed CVE-2025-40083 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811733 -> 811751

Fixed

Fixed a race condition where unmounting file systems monitored by inotify or fanotify could result in kernel crash.

Security

Fixed CVE-2025-40042 in the Linux kernel.

November 07, 2025

Change

cos-117-18613-439-16

Kernel Docker Containerd GPU Drivers
COS-6.6.111 v24.0.9 v1.7.28 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811728 -> 811733

Security

Fixed CVE-2025-40105 in the Linux kernel.

Security

Fixed CVE-2025-40052 in the Linux kernel.

Security

Fixed CVE-2025-40049 in the Linux kernel.

Security

Fixed CVE-2025-40099 in the Linux kernel.

Security

Fixed CVE-2025-40103 in the Linux kernel.

Fixed

Fixed bcache latency spikes.

Security

Fixed CVE-2025-40035 in the Linux kernel.

Security

Fixed CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 in app-containers/runc.

Security

Fixed CVE-2025-40040 in the Linux kernel.

Security

Fixed CVE-2025-40044 in the Linux kernel.

November 03, 2025

Change

cos-117-18613-439-12

Kernel Docker Containerd GPU Drivers
COS-6.6.111 v24.0.9 v1.7.28 See List
Security

Fixed CVE-2025-38073 in the Linux kernel.

Security

Fixed CVE-2025-40078 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811785 -> 811728

Security

Fixed CVE-2025-40038 in the Linux kernel.

Security

Fixed CVE-2025-40070 in the Linux kernel.

October 27, 2025

Change

cos-117-18613-439-9

Kernel Docker Containerd GPU Drivers
COS-6.6.111 v24.0.9 v1.7.28 See List
Security

Fixed CVE-2025-11413 and CVE-2025-11414 in binutils-libs.

Fixed

Upgraded sys-apps/less to v685.

Security

Fixed CVE-2025-11495 in binutils-libs.

Fixed

Added support for NVIDIA driver v535.274.02 and v570.195.03.

Security

Fixed CVE-2025-11494 in binutils-libs.

Security

Fixed CVE-2025-11412 in binutils-libs.

Fixed

Upgraded sys-apps/hwdata to v0.400.

Change

Updated app-containers/runc to v1.2.7.

October 20, 2025

Change

cos-117-18613-439-2

Kernel Docker Containerd GPU Drivers
COS-6.6.111 v24.0.9 v1.7.28 See List
Announcement
Fixed

Upgraded net-nds/rpcbind to v1.2.8.

Fixed

Upgraded dev-lang/go to v1.23.12.

Fixed

Added task information collection to sosreports.

Fixed

Upgraded sys-apps/gentoo-functions to v1.7.4.

Security

Fixed CVE-2025-41244 in app-emulation/open-vm-tools.

Fixed

Upgraded app-admin/sudo to v1.9.17_p2.

Fixed

Updated golang.org/x/crypto, golang.org/x/net, and golang.org/x/oauth2 in kubelet and kubectl.

Security

Fixed KCTF-cd8ae32 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811830 -> 811764

Fixed

Reduced gcr_wait_online retry gap.

Security

Fixed CVE-2025-39961 in the Linux kernel.

Fixed

Upgraded app-admin/google-guest-configs to v20250805.00.

Security

Fixed KCTF-6bb73db in the Linux Kernel.

Fixed

Upgraded dev-libs/expat to v2.7.3.

Fixed

Upgraded dev-db/sqlite to v3.50.3.

October 13, 2025

Change

cos-117-18613-339-97

Kernel Docker Containerd GPU Drivers
COS-6.6.105 v24.0.9 v1.7.28 See List
Security

Fixed CVE-2025-11081, CVE-2025-11082 and CVE-2025-11083 in sys-libs/binutils-libs.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811755 -> 811830

Fixed

Upgraded app-admin/node-problem-detector to v0.8.22.

Security

Fixed CVE-2025-39947 in the Linux kernel.

Feature

Added support for NVIDIA driver v580.95.05. Updated all latest driver version and default driver versions for NVIDIA_GB200 and NVIDIA_B200 to v580.95.05.

Security

Fixed CVE-2025-23143 in the Linux kernel.

October 09, 2025

Change

cos-117-18613-339-89

Kernel Docker Containerd GPU Drivers
COS-6.6.105 v24.0.9 v1.7.28 See List
Fixed

Updated toolbox container image tag to v20251002.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811788 -> 811755

Security

Fixed CVE-2025-39953 in the Linux kernel.

Fixed

Partially fixed the system not responding caused by excessive contention among writeback kworkers when switching a large number of inodes between cgroups.

Security

Fixed CVE-2025-39931 in the Linux kernel.

Fixed

Upgraded sys-apps/hwdata to v0.399.

Security

Fixed KCTF-134121b in the Linux kernel.

October 06, 2025

Change

cos-117-18613-339-84

Kernel Docker Containerd GPU Drivers
COS-6.6.105 v24.0.9 v1.7.28 See List
Security

Fixed CVE-2025-50181 in dev-python/urllib3.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811817 -> 811788

Security

Fixed CVE-2025-39882 in the Linux kernel.

Security

Fixed CVE-2025-39911 in the Linux kernel.

Security

Fixed CVE-2025-39886 in the Linux kernel.

Security

Fixed CVE-2025-39914 in the Linux kernel.

Security

Fixed CVE-2025-22106 in the Linux kernel.

Security

Fixed CVE-2025-39913 in the Linux kernel.

Fixed

Add support for NVIDIA MFT Tools v4.33.0.

Security

Fixed KCTF-1b34cbb in the Linux kernel.

September 29, 2025

Change

cos-117-18613-339-77

Kernel Docker Containerd GPU Drivers
COS-6.6.105 v24.0.9 v1.7.28 See List
Fixed

Updated golang.org/x/crypto, golang.org/x/net, golang.org/x/oauth2, and github.com/golang-jwt/jwt/v4 in Docker.

Security

Updated dev-python/jinja to v3.1.6. This resolves CVE-2024-56326, CVE-2024-56201 and CVE-2025-27516.

Security

Fixed KCTF-0aeb54a in the Linux Kernel.

Security

Fixed CVE-2025-39881 in the Linux kernel.

Security

Fixed CVE-2025-39883 in the Linux kernel.

Security

Fixed CVE-2025-40300 in the Linux kernel.

September 24, 2025

Change

cos-117-18613-339-70

Kernel Docker Containerd GPU Drivers
COS-6.6.105 v24.0.9 v1.7.28 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811774 -> 811794

Security

Upgraded dev-libs/libxml2 to version 2.13.9. This fixes CVE-2025-9714.

Fixed

Updated the Linux kernel to v6.6.105.

Fixed

Upgraded dev-libs/libxslt to version 1.1.43-r1.

Change

Updated cos-gpu-installer to v2.5.7.

Fixed

Updated golang.org/x/crypto in google-osconfig-agent to v0.31.0.

Change

Enabled Coherent Driver Memory Management by default when installing GPU drivers on GB2000.

Fixed

Added support for NVIDIA driver v580.82.07. Updated all latest driver version and default driver versions for NVIDIA_GB200 and NVIDIA_B200 to v580.82.07.

September 16, 2025

Change

cos-117-18613-339-65

Kernel Docker Containerd GPU Drivers
COS-6.6.97 v24.0.9 v1.7.28 See List
Security

Fixed CVE-2025-38571 in the Linux kernel.

Security

Fixed CVE-2025-38528 in the Linux kernel.

Security

Fixed CVE-2025-38639 in the Linux kernel.

Security

Fixed CVE-2025-38588 in the Linux kernel.

Security

Fixed CVE-2025-38566 in the Linux kernel.

Security

Fixed CVE-2025-38645 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811749 -> 811774

Security

Fixed CVE-2025-38565 in the Linux kernel.

Security

Fixed CVE-2025-38587 in the Linux kernel.

Security

Fixed CVE-2025-38608 in the Linux kernel.

Security

Fixed CVE-2025-38572 in the Linux kernel.

Feature

Added support for NVIDIA MFT Tools on arm64.

Security

Fixed CVE-2025-38568 in the Linux kernel.

Security

Fixed CVE-2025-38527 in the Linux kernel.

Security

Fixed CVE-2025-38622 in the Linux kernel.

Feature

Added GDRCopy kernel module for NVIDIA drivers.

Security

Fixed CVE-2025-38539 in the Linux kernel.

Security

Fixed CVE-2025-38640 in the Linux kernel.

September 08, 2025

Change

cos-117-18613-339-56

Kernel Docker Containerd GPU Drivers
COS-6.6.97 v24.0.9 v1.7.28 See List
Security

Fixed CVE-2025-38351 in the Linux kernel.

Security

Fixed CVE-2025-38322 in the Linux kernel.

Security

Fixed CVE-2025-38676 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811812 -> 811749

September 02, 2025

Change

cos-117-18613-339-52

Kernel Docker Containerd GPU Drivers
COS-6.6.97 v24.0.9 v1.7.28 See List
Security

Fixed KCTF-62708b9 in the Linux kernel.

Security

Fixed KCTF-aba0c94 in the Linux kernel.

Security

Fixed CVE-2025-6052 in dev-libs/glib.

Fixed

Upgraded sys-apps/hwdata to v0.398.

Security

Fixed KCTF-6db015f in the Linux kernel.

Fixed

Upgraded sys-apps/file to v5.46-r3.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811728 -> 811812

August 25, 2025

Change

cos-117-18613-339-44

Kernel Docker Containerd GPU Drivers
COS-6.6.97 v24.0.9 v1.7.28 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811771 -> 811728

Security

Fixed KCTF-abad3d0 in the Linux kernel.

Feature

Added IPv6 support for machines using the IDPF driver.

Feature

Disabled DNSSEC by default for COS TPU VMs.

Fixed

Added support for the Lustre 2.14.0_p216 drivers.

August 18, 2025

Change

cos-117-18613-339-39

Kernel Docker Containerd GPU Drivers
COS-6.6.97 v24.0.9 v1.7.28 See List
Security

Upgraded sys-libs/binutils-libs to version 2.45. This fixes CVE-2025-8224,CVE-2025-8225 and CVE-2025-1153.

Security

Fixed KCTF-01d3c84 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811830 -> 811771

August 14, 2025

Change

cos-117-18613-339-36

Kernel Docker Containerd GPU Drivers
COS-6.6.97 v24.0.9 v1.7.28 See List
Security

Fixed CVE-2025-38499 in the linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811765 -> 811830

August 12, 2025

Change

cos-117-18613-339-32

Kernel Docker Containerd GPU Drivers
COS-6.6.97 v24.0.9 v1.7.28 See List
Feature

Added NVIDIA GPU driver's R580 branch. Updated the LATEST GPU driver label to version 580.65.06.

Fixed

Upgraded virtual/logger to v0-r2.

Security

Upgraded dev-vcs/git to version 2.49.1. This fixes CVE-2025-48385, CVE-2025-27613, CVE-2025-27614, CVE-2025-48384, CVE-2025-46835.

Security

Fixed CVE-2024-6174 in cloud-init.

Security

Fixed CVE-2024-11584 in cloud-init.

Security

Upgraded dev-libs/glib to 2.82.5. This resolves CVE-2024-52533.

Fixed

Fixed an issue where the cpuidle driver selected for some machine types would cause inflated reports of high CPU usage.

Fixed

Updated containerd to v1.7.28.

Security

Added support for Nvidia driver version 570.172.08. This fixes CVE-2025-23279.

Fixed

Updated app-admin/node-problem-detector to 0.8.21.

Security

Upgraded net-misc/netplan to 1.1.2. This fixes CVE-2022-4968.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811775 -> 811765

Fixed

Updated dev-python/requests to v2.32.4.

Security

Patched openssl to fix CVE-2023-50782 affecting dev-python/crytography.

Security

Added support for Nvidia driver version 535.261.03. This fixes CVE-2025-23286 and CVE-2025-23279.

Security

Fixed CVE-2025-8058 in glibc.

Security

Fixed KCTF-bfebdb8 in the kernel.

Security

Upgraded urllib3 to version 1.26.18. This fixes CVE-2021-33503, CVE-2023-43804, and CVE-2023-45803.

August 06, 2025

Change

cos-117-18613-339-26

Kernel Docker Containerd GPU Drivers
COS-6.6.97 v24.0.9 v1.7.27 See List
Fixed

Fixed an issue where the cpuidle driver selected for some machine types would cause inflated reports of high CPU usage.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811775 -> 811788

Security

Fixed CVE-2024-6174 in cloud-init.

Fixed

Upgraded virtual/logger to v0-r2.

Fixed

Updated dev-python/requests to v2.32.4.

Security

Fixed CVE-2024-11584 in cloud-init.

Security

Upgraded net-misc/netplan to 1.1.2. This fixes CVE-2022-4968.

Security

Added support for Nvidia driver version 570.172.08. This fixes CVE-2025-23279.

Security

Upgraded dev-libs/glib to 2.82.5. This resolves CVE-2024-52533.

Security

Upgraded dev-vcs/git to version 2.49.1. This fixes CVE-2025-48385, CVE-2025-27613, CVE-2025-27614, CVE-2025-48384, CVE-2025-46835.

Security

Patched openssl to fix CVE-2023-50782 affecting dev-python/cryptography.

Security

Added support for Nvidia driver version 535.261.03. This fixes CVE-2025-23286 and CVE-2025-23279.

July 28, 2025

Change

cos-117-18613-339-11

Kernel Docker Containerd GPU Drivers
COS-6.6.97 v24.0.9 v1.7.27 See List
Announcement
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811820 -> 811775

Fixed

Upgraded sys-process/procps to v4.0.5-r2.

Fixed

Upgraded sys-process/lsof to v4.99.5.

Fixed

Upgraded sys-libs/talloc to v2.4.3.

Fixed

Upgraded dev-db/sqlite to v3.50.1.

Security

Fixed KCTF-5e28d5a in the Linux kernel.

Fixed

Upgraded app-admin/google-guest-configs to v20250516.00.

Fixed

Upgraded dev-lang/go to v1.23.9.

Fixed

Upgraded app-containers/cni-plugins to v1.7.1.

Security

Fixed CVE-2024-26130 in dev-python/cryptography.

Security

Upgraded sqlite to v3.50.2. This resolves CVE-2025-6965.

Fixed

Upgraded net-fs/cifs-utils to v7.4.

Fixed

Updated app-misc/jq to v1.8.1.

Fixed

The NFS access cache is no longer cleared on login by default. To use the old behavior, load the NFS module with the nfs_fasc=1 module parameter.

Fixed

Fixed a kernel bug which caused some NVME disk IO errors to be ignored, potentially resulting in dropped writes.

Fixed

Upgraded sys-libs/libcap to v2.76.

Fixed

Upgraded app-arch/gzip to v1.14.

July 21, 2025

Change

cos-117-18613-263-75

Kernel Docker Containerd GPU Drivers
COS-6.6.93 v24.0.9 v1.7.27 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811784 -> 811820

Feature

Added ARM support for the Lustre 2.14.0 drivers.

Fixed

Fixed an issue where some workloads could cause a full system hang when running close to their memory limit.

Change

Updated the NVIDIA GPU driver policy for New Feature Branch (NFB) drivers. The LATEST tag has been updated to point to the stable 570.133.20 Production Branch. The 575.57.08 NFB driver remains available for development and testing but must now be selected by its specific version number. Removed 575.57.08 NFB driver support for NVIDIA_GB200 machine.

Security

Fixed KCTF-103406b in the Linux kernel.

July 14, 2025

Change

cos-117-18613-263-66

Kernel Docker Containerd GPU Drivers
COS-6.6.93 v24.0.9 v1.7.27 See List
Fixed

Updated google-guest-agent to v20250701.01.

Security

Upgraded vim, vim-core to version 9.1.1500. This fixes CVE-2025-26603, CVE-2025-27423, CVE-2025-29768, CVE-2025-1215, CVE-2025-24014, CVE-2025-22134.

Security

Updated app-editors/nano to v8.5. This resolves CVE-2024-5742.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811799 -> 811784

Change

Upgraded nvidia-container-toolkit to v1.17.8. This fixes CVE-2025-23266.

July 07, 2025

Change

cos-117-18613-263-58

Kernel Docker Containerd GPU Drivers
COS-6.6.93 v24.0.9 v1.7.27 See List
Security

Upgraded app-admin/sudo to v1.9.17_p1. This resolves CVE-2025-32462 and CVE-2025-32463.

June 30, 2025

Change

cos-117-18613-263-56

Kernel Docker Containerd GPU Drivers
COS-6.6.93 v24.0.9 v1.7.27 See List
Fixed

Upgraded dev-libs/libusb to v1.0.29.

Fixed

Added support for the Lustre 2.14.0_p212 drivers.

Security

Upgraded elfutils to version 0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.

Fixed

Upgraded sys-apps/less to v679.

Security

Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811785 -> 811719

June 23, 2025

Change

cos-117-18613-263-49

Kernel Docker Containerd GPU Drivers
COS-6.6.93 v24.0.9 v1.7.27 See List
Security

Updated the Linux kernel to v6.6.93. This includes mitigations for CVE-2024-28956, which may negatively impact the performance of Intel machine types.

Security

Fixed KCTF-d35acc1 in the Linux kernel.

Feature

Added a kernel patch to address bcache latency.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811766 -> 811785

June 18, 2025

Change

cos-117-18613-263-45

Kernel Docker Containerd GPU Drivers
COS-6.6.87 v24.0.9 v1.7.27 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811775 -> 811766

Security

Upgraded app-misc/jq to v1.8.0. This fixes CVE-2025-48060.

June 17, 2025

Change

cos-117-18613-263-42

Kernel Docker Containerd GPU Drivers
COS-6.6.87 v24.0.9 v1.7.27 See List
Feature

Fixed CVE-2024-41110 in Docker.

Security

Fixed CVE-2025-47273 in dev-python/setuptools.

Change

Added support for the Lustre 2.14.0_p198 drivers.

Security

Updated systemd to v254.26. This resolves CVE-2025-4598.

Feature

Added support for Nvidia driver version 575.57.08.

Security

Fixed CVE-2025-37800 in the Linux kernel.

Security

Fixed KCTF-ac9fe7d in the kernel.

Security

Fixed CVE-2025-37803 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811818 -> 811775

Change

Updated cos-gpu-installer to v2.5.3.

June 02, 2025

Change

cos-117-18613-263-24

Kernel Docker Containerd GPU Drivers
COS-6.6.87 v24.0.9 v1.7.27 See List
Security

Fixed KCTF-8478a72 in the Linux kernel.

Security

Fixed CVE-2024-23337 in app-misc/jq.

Fixed

Updated cos-gpu-installer to v2.5.2: Added support for OTHER/NO_GPU cases to enable GPU driver preloading on the ARM64 architecture and added support for IMEX Driver configuration installation for NVIDIA_GB200 machine.

Fixed

Upgraded sys-apps/less to v678.

Security

Fixed KCTF-3f98113 in the Linux kernel.

Security

Fixed CVE-2024-43840 in the Linux kernel.

May 27, 2025

Change

cos-117-18613-263-19

Kernel Docker Containerd GPU Drivers
COS-6.6.87 v24.0.9 v1.7.27 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811793 -> 811830

Feature

Support NVIDIA MFT Tools on COS.

Security

Fixed CVE-2025-46836 in sys-apps/net-tools.

Feature

Inject IMEX channel char device for GB200 GPUs.

Security

Fixed CVE-20250-3198 in sys-libs/bintuils-libs.

Security

Fixed KCTF-b3bf8f6 in the Linux kernel.

May 19, 2025

Change

cos-117-18613-263-14

Kernel Docker Containerd GPU Drivers
COS-6.6.87 v24.0.9 v1.7.27 See List
Fixed

Increased kdump memory reservation.

May 12, 2025

Change

cos-117-18613-263-13

Kernel Docker Containerd GPU Drivers
COS-6.6.87 v24.0.9 v1.7.27 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811816 -> 811830

Security

Fixed KCTF-3df275e in the Linux kernel.

Change

Upgraded app-admin/google-guest-configs to v20250501.00.

Security

Updated apparmor to 3.1.6. This fixes CVE-2016-1585.

Change

Added support for 7th generation TPU devices.

Security

Upgraded containerd to 1.7.27. Fixes CVE-2024-40635.

Fixed

Fixed issue where modinfo could not display module signatures.

May 05, 2025

Change

cos-117-18613-263-4

Kernel Docker Containerd GPU Drivers
COS-6.6.87 v24.0.9 v1.7.24 See List
Announcement
Fixed

Upgraded net-libs/libtirpc to v1.3.6.

Fixed

Upgraded dev-libs/double-conversion to v3.3.1.

Fixed

Upgraded net-nds/rpcbind to v1.2.7.

Fixed

Upgraded app-admin/sudo to v1.9.16_p2-r1.

Fixed

Upgraded dev-db/sqlite to v3.49.1.

Fixed

Upgraded net-fs/cifs-utils to v7.3, Upgraded sys-libs/talloc to v2.4.2.

Fixed

Upgraded net-libs/libnetfilter_conntrack to v1.1.0.

Fixed

Upgraded sys-libs/libcap to v2.71.

Fixed

Upgraded sys-apps/grep to v3.12.

Security

Updated dev-vcs/git to version 2.49.0. This fixed CVE-2024-52006, CVE-2024-50349

Security

Updated NVIDIA GPU drivers to v535.247.01 for default/ R535, v550.163.01 for R550 and v570.133.20 for latest/R570. This resolves CVE-2025-23244.

Fixed

Upgraded dev-libs/nss to v3.109.

Security

Fix CVE-2025-32414, CVE-2025-32415 in dev-libs/libxml2.

Fixed

Upgraded dev-libs/expat to v2.7.1.

Security

Fixed CVE-2025-22035 in the Linux kernel.

Security

Update dev-go/net in policy manager to v0.39.0. This fixes CVE-2025-22870.

Security

Fixed KCTF-342debc in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811753 -> 811816

Fixed

Upgraded sys-libs/libseccomp to v2.6.0-r2.

Fixed

Upgraded app-admin/google-guest-configs to v20250328.00.

Fixed

Upgraded sys-apps/acl to v2.3.2-r2.

Fixed

Upgraded app-containers/cni-plugins to v1.6.2.

Security

Fixed CVE-2025-1178,CVE-2025-1182 and CVE-2025-1181 in sys-libs/binutils-libs.

Security

Fixed CVE-2025-22097 in the Linux kernel.

Fixed

Upgraded app-arch/unzip to v6.0_p29.

Fixed

Upgraded sys-apps/gentoo-functions to v1.7.3.

Fixed

Upgraded net-dns/libidn2 to v2.3.8.

Fixed

Upgraded dev-lang/go to v1.23.8.

Fixed

Upgraded app-containers/docker-credential-helpers to v0.9.3.

Fixed

Upgraded sys-apps/makedumpfile to v1.7.7.

April 29, 2025

Change

cos-117-18613-164-124

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811760 -> 811753

Security

Fixed CVE-2025-32728 in net-misc/openssh.

April 25, 2025

Change

cos-117-18613-164-121

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2025-21908 in the Linux kernel.

Fixed

Reverted a change in the linux kernel which caused nfs directories to unexpectedly be mounted as ro instead of rw.

Security

Fixed CVE-2025-21991 in the Linux kernel.

Security

Fixed CVE-2025-21962 in the Linux kernel.

Security

Fixed CVE-2025-21980 in the Linux kernel.

Security

Fixed CVE-2025-22005 in the Linux kernel.

Security

Fixed CVE-2025-21922 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811760 -> 811799

Security

Fixed CVE-2025-21919 in the Linux kernel.

Security

Fixed CVE-2025-21963 in the Linux kernel.

Security

Fixed CVE-2024-48615 in app-arch/libarchive.

Fixed

Upgraded app-admin/node-problem-detector to v0.8.20.

Security

Fixed CVE-2025-21964 in the Linux kernel.

Security

Fixed CVE-2025-21920 in the Linux kernel.

Security

Fixed CVE-2025-21997 in the Linux kernel.

Change

Updated cos-gpu-installer to v2.5.0: Support IMEX Driver installation for NVIDIA_GB200 GPU device.

Security

Fixed CVE-2025-21959 in the Linux kernel.

Security

Fixed CVE-2025-21898 in the Linux kernel.

April 14, 2025

Change

cos-117-18613-164-109

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2025-21853 in the Linux kernel.

Security

Fixed CVE-2024-58070 in the Linux kernel.

Security

Fixed CVE-2025-21887 in the Linux kernel.

Fixed

Upgraded sys-apps/diffutils to v3.11-r2.

Fixed

Modified toolbox to use unified cgroup hierarchy mode, when possible, instead of hybrid mode.

Security

Fixed CVE-2025-21763 in the Linux kernel.

Security

Fixed CVE-2025-21999 in the Linux kernel.

Fixed

Upgraded dev-libs/libusb to v1.0.28.

Security

Fixed CVE-2025-21867 in the Linux kernel.

Security

Fixed CVE-2024-58083 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811785 -> 811760

March 31, 2025

Change

cos-117-18613-164-98

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2025-21762 in the Linux kernel.

Security

Fixed CVE-2025-21764 in the Linux kernel.

Security

Fixed CVE-2024-56549 in the Linux kernel.

Security

Fixed CVE-2025-21727 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811744 -> 811785

Security

Fixed CVE-2025-21796 in the Linux kernel.

Security

Fixed CVE-2025-21760 in the Linux kernel.

Security

Updated dev-libs/expat to v2.7.0. This fixes CVE-2024-8176.

Security

Fixed CVE-2024-57979 in the Linux kernel.

Security

Fixed CVE-2025-21726 in the Linux kernel.

Security

Fixed CVE-2025-21759 in the Linux kernel.

Security

Fixed CVE-2025-21812 in the Linux kernel.

Security

Fixed CVE-2024-57977 in the Linux kernel.

Security

Fixed KCTF-0c3057a in the Linux kernel.

Security

Fixed CVE-2024-50138 in the Linux kernel.

March 24, 2025

Change

cos-117-18613-164-93

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811752 -> 811744

Security

Fixed KCTF-647cef2 in the Linux kernel.

Security

Fixed CVE-2025-21785 in the Linux kernel.

Feature

Added support for the Lustre 2.14.0 client drivers.

Security

Fixed CVE-2025-21716 in the Linux kernel.

Fixed

Fixed a race condition that could cause a kernel panic.

Change

Fixed an issue that resulted in missing grub boot measurements in some machine configurations.

Feature

Added support for NVIDIA GB200 GPU with 570.124.06 GPU driver. This driver version has been assigned the latest, default, and R570 tags for this GPU type.

Fixed

Upgraded dev-lang/go to v1.23.7.

Security

Fixed CVE-2024-58005 in the Linux kernel.

March 17, 2025

Change

cos-117-18613-164-81

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2024-58017 in the Linux kernel.

Security

Fixed CVE-2025-21779 in the Linux kernel.

Security

Fixed CVE-2025-21858 in the Linux kernel.

Security

Fixed CVE-2023-45288 in app-containers/docker.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811757 -> 811752

Security

Fixed CVE-2024-57996 in the Linux kernel.

Security

Fixed CVE-2024-58088 in the Linux kernel.

Security

Fixed CVE-2025-21844 in the Linux kernel.

Security

Fixed CVE-2025-21791 in the Linux kernel.

Security

Fixed CVE-2025-21814 in the Linux kernel.

Security

Fixed CVE-2025-21745 in the Linux kernel.

Feature

Added support for NVIDIA 570.124.06 GPU driver. Updated the R570, LATEST GPU driver label to version 570.124.06 for all GPU devices. Updated the DEFAULT GPU driver label to version 570.124.06 for NVIDIA_B200 and NVIDIA_H200 GPU devices.

Security

Fixed CVE-2025-21854 in the Linux kernel.

Security

Fixed CVE-2025-21863 in the Linux kernel.

Feature

Added support for iRDMA devices.

Security

Fixed CVE-2025-21864 in the Linux kernel.

Security

Fixed CVE-2025-21846 in the Linux kernel.

Security

Fixed CVE-2025-21857 in the Linux kernel.

Fixed

Upgraded net-misc/socat to v1.8.0.3.

March 12, 2025

Change

cos-117-18613-164-68

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Fixed

Disabled martian logging for ConnectX-7 network cards. These cards only communicate locally, but martian logging during communications with the host can lead to a race condition which causes GID table construction to sometimes fail.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811762 -> 811757

Security

Fixed CVE-2024-53589 in sys-libs/libutils-libs.

Security

Fixed CVE-2025-26465 and CVE-2025-26466 in net-misc/openssh.

Fixed

Upgraded sys-apps/which to v2.23.

Security

Upgraded dev-go/crypto to v0.35.0. This fixes CVE-2025-22869.

Security

Fixed CVE-2024-50017 in the Linux kernel.

Fixed

Fixed console TTY leak in runc shim in containerd.

Security

Updated dev-go/oauth2 to v0.27.0. This fixes CVE-2025-22868.

Fixed

Upgraded sys-apps/diffutils to v3.11-r1.

Feature

Updated cos-gpu-installer to v2.4.8: Add the -skip-nvidia-smi flag to disable the execution of nvidia-smi verification during gpu driver installation.

Security

Upgraded dev-libs/libxml2 to v1.12.10. This fixes CVE-2025-27113.

Security

Fixed KCTF-8802766 in the Linux kernel.

Security

Fixed KCTF-638ba50 in the Linux kernel.

Feature

Applied Intel patches to add iRDMA support in the Linux kernel.

Security

Fixed CVE-2024-50146 in the Linux kernel.

Security

Upgraded net-misc/wget to v1.25.0. This fixes CVE-2024-10524.

Security

Fixed KCTF-fcdd224 in the Linux kernel.

March 03, 2025

Change

cos-117-18613-164-49

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Fixed

Upgraded moby/buildkit to v0.12.5. This fixes CVE-2024-23653 in app-containers/docker v24.0.9.

Security

Fixed CVE-2025-21690 in the Linux kernel.

February 24, 2025

Change

cos-117-18613-164-47

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2025-0395 in sys-libs/glibc.

Security

Fixed CVE-2024-13176 in dev-libs/openssl.

Security

Fixed CVE-2024-57951 in the Linux kernel.

Change

Updated app-admin/google-guest-configs to v20250207.00.

Security

Fixed CVE-2024-9287 in dev-lang/python.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811817 -> 811792

Security

Fixed CVE-2024-57949 in the Linux kernel.

February 18, 2025

Change

cos-117-18613-164-38

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2024-9287 in dev-lang/python.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811817 -> 811794

Security

Fixed CVE-2025-0395 in sys-libs/glibc.

February 10, 2025

Change

cos-117-18613-164-28

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2025-21666 in the Linux kernel.

Security

Fixed CVE-2024-49994 in the Linux kernel.

Security

Fixed CVE-2025-21667 in the Linux kernel.

Security

Fixed CVE-2024-50304 in the Linux kernel.

Feature

Support for NVIDIA B200 GPU – Added support for the R570 driver series, including version 570.86.15. This version has been assigned the latest, default, and R570 tags.

Fixed

Upgraded app-admin/fluent-bit to v3.1.10.

Change

Updated Konlet to v0.13.4.

Security

Fixed CVE-2025-0840 in binutils.

Security

Fixed CVE-2025-21673 in the Linux kernel.

Security

Fixed CVE-2024-50014 in the Linux kernel.

Security

Fixed CVE-2025-21671 in the Linux kernel.

Security

Fixed CVE-2025-21665 in the Linux kernel.

Fixed

Upgraded sys-apps/hwdata to v0.391.

Feature

Updated cos-gpu-installer to v2.4.7: 1.Added Support for NVIDIA B200 GPU. 2.Enabled --prepare-build-tools flag to preload GPU driver metadata for ARM64

Security

Fixed CVE-2025-21670 in the Linux kernel.

Security

Fixed CVE-2025-21669 in the Linux kernel.

Change

Updated the default tag of the GPU driver supporting the NVIDIA H200 GPU device to 570.86.15.

Security

Fixed CVE-2025-21683 in the Linux kernel.

February 03, 2025

Change

cos-117-18613-164-13

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Feature

Backported Intel TDX (Trust Domain Extensions) and confidential computing patches from Linux kernel 6.7 upstream to enable TDX feature support.

Feature

Added NVIDIA GPU driver's R570 branch. Updated the LATEST GPU driver label to version 570.86.15.

Feature

Enabled Grace platform support: Enabled DMA-BUF shared memory support for the ARM64 kernel.

Feature

Enabled Grace platform support: Enabled memory_hotplug and device_private in the ARM64 kernel.

Security

Fixed CVE-2024-53170 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811776 -> 811757

Feature

Enabled Grace platform support: Enabled SMMU (v3) for ARM64 kernel.

Feature

Enabled Grace platform support: Enabled ATS/PASID(PCI) for ARM64 kernel.

Feature

Enabled ECC kernel modules required for confidential GPU functionality.

Security

Fixed KCTF-bc50835 in the Linux kernel.

Security

Fixed CVE-2024-53124 in the Linux kernel.

January 27, 2025

Change

cos-117-18613-164-4

Kernel Docker Containerd GPU Drivers
COS-6.6.72 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2024-56617 in the Linux kernel.

Security

Fixed CVE-2024-57890 in the Linux kernel.

Security

Fixed CVE-2024-45306 and CVE-2024-47814 in vim.

Announcement
Security

Fixed CVE-2024-45306 and CVE-2024-47814 in vim-core.

Security

Update NVIDIA GPU drivers to v535.230.02 for default/R535 and v550.144.03 for R550 for all GPUs. This resolves CVE-2024-53869, CVE-2024-0150, CVE-2024-0149, CVE-2024-0147 and CVE-2024-0131.

Fixed

Upgraded dev-python/configobj to v5.0.9.

Security

Fixed CVE-2024-56369 in the Linux kernel.

Fixed

Upgraded sys-apps/gentoo-functions to v1.7.2.

Fixed

Upgraded sys-apps/file to v5.46-r2.

Security

Fixed CVE-2024-55916 in the Linux kernel.

Security

Fixed CVE-2024-56615 in the Linux kernel.

Security

Fixed CVE-2024-57841 in the Linux kernel.

Fixed

Upgraded app-arch/lz4 to v1.10.0-r1.

Fixed

Upgraded dev-libs/nss to v3.105.

Fixed

Upgraded app-containers/docker-credential-gcr to v2.1.25.

Security

Upgraded dev-libs/libxml2 to version 2.12.9. This fixes CVE-2024-40896.

Fixed

Upgraded app-admin/google-osconfig-agent to v20240927.00.

Fixed

Upgraded app-emulation/cloud-init to v23.4.4.

Fixed

Upgraded dev-db/sqlite to v3.46.1.

Security

Fixed CVE-2024-54683 in the Linux kernel.

Security

Fixed CVE-2024-56779 in the Linux kernel.

Feature

Added NVIDIA GPU drivers R565 branch - Update R565, latest driver to v565.57.01.

Security

Fixed CVE-2024-53166 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811796 -> 811776

Fixed

Upgraded net-libs/libtirpc to v1.3.5.

January 17, 2025

Change

cos-117-18613-75-114

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2024-56786 in the Linux kernel.

Security

Fixed CVE-2024-56783 in the Linux kernel.

Security

Fixed CVE-2024-56755 in the Linux kernel.

Security

Fixed CVE-2024-56720 in the Linux kernel.

Security

Upgraded rsync to version 3.3.0-r2. This fixes CVE-2024-12084, CVE-2024-12085, CVE-2024-12086, CVE-2024-12087, CVE-2024-12088, and CVE-2024-12747.

Security

Fixed CVE-2024-53185 in the Linux kernel.

Security

Fixed CVE-2024-56780 in the Linux kernel.

Security

Fixed CVE-2024-56600 in the Linux kernel.

Security

Fixed CVE-2024-56672 in the Linux kernel.

Security

Fixed CVE-2024-56664 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811744 -> 811796

Security

Fixed CVE-2024-56756 in the Linux kernel.

Security

Fixed CVE-2024-53173 in the Linux kernel.

Security

Fixed CVE-2024-56675 in the Linux kernel.

Security

Fixed CVE-2024-56658 in the Linux kernel.

Security

Fixed CVE-2024-53128 in the Linux kernel.

Security

Fixed CVE-2024-53206 in the Linux kernel.

Security

Fixed CVE-2024-53202 in the Linux kernel.

Security

Fixed CVE-2024-56601 in the Linux kernel.

January 13, 2025

Change

cos-117-18613-75-102

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2024-56614 in the Linux kernel.

Security

Fixed CVE-2024-56606 in the Linux kernel.

Fixed

Upgraded sys-apps/file to v5.46-r1.

Security

Fixed CVE-2024-56745 in the Linux kernel.

Security

Fixed CVE-2024-53146 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811756 -> 811744

Security

Fixed CVE-2024-56694 in the Linux kernel.

Security

Fixed CVE-2024-56688 in the Linux kernel.

Security

Fixed CVE-2024-53096 in the Linux kernel.

Change

Upgraded nvidia-container-toolkit to v1.17.3.

Security

Fixed CVE-2024-56739 in the Linux kernel.

Fixed

Upgraded net-misc/socat to v1.8.0.2.

Security

Fixed CVE-2024-53151 in the Linux kernel.

Security

Fixed CVE-2024-56729 in the Linux kernel.

Security

Fixed CVE-2024-56763 in the Linux kernel.

Security

Fixed CVE-2024-56760 in the Linux kernel.

January 06, 2025

Change

cos-117-18613-75-91

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2023-52920 in the Linux kernel.

Security

Fixed KCTF-5eb7de8 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811782 -> 811756

Security

Fixed KCTF-f8d4bc4 in the Linux kernel.

January 02, 2025

Change

cos-117-18613-75-89

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2024-53121 in the Linux kernel.

Security

Fixed CVE-2024-53135 in the Linux kernel.

Security

Upgraded nvidia-container-toolkit to v1.17.0. This fixes CVE-2024-0134.

Security

Fixed CVE-2024-49934 in the Linux kernel.

Security

Fixed CVE-2024-53091 in the Linux kernel.

Security

Upgraded dev-go/crypto to v0.31.0. This fixes CVE-2024-45337.

Security

Fixed CVE-2024-53113 in the Linux kernel.

Fixed

Updated google.golang.org/grpc to v1.56.3 and upgrade golang.org/x/net to v0.23.0 in docker and cri-tools. This fixes CVE-2023-44487 and CVE-2023-45288.

Security

Fixed CVE-2024-50191 in the Linux kernel.

Security

Fixed CVE-2024-53100 in the Linux kernel.

Security

Fixed CVE-2024-49926 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811809 -> 811782

Security

Fixed CVE-2024-53099 in the Linux kernel.

Security

Fixed CVE-2024-53119 in the Linux kernel.

Security

Update dev-go/net in policy manager to v0.33.0. This fixes CVE-2024-45338.

Security

Fixed CVE-2024-53097 in the Linux kernel.

Security

Fixed CVE-2024-53142 in the Linux kernel.

Security

Fixed CVE-2024-50256 in the Linux kernel.

Security

Fixed CVE-2024-53136 in the Linux kernel.

Security

Fixed CVE-2024-53140 in the Linux kernel.

Security

Fixed CVE-2024-53141 in the Linux kernel.

Security

Fixed CVE-2024-53093 in the Linux kernel.

December 16, 2024

Change

cos-117-18613-75-72

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.24 See List
Change

Upgraded sys-apps/hwdata to v0.390.

Fixed

Disabled CONFIG_DEBUG_PREEMPT in the Linux kernel. This should improve performance for some workloads.

Security

Fixed CVE-2024-50186 in the Linux kernel.

Change

Upgraded sys-apps/file to v5.46.

Change

Updated app-admin/google-guest-configs to v20241205.00.

December 09, 2024

Change

cos-117-18613-75-66

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.24 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811804 -> 811763

Feature

Support NVIDIA_H200 GPU - Added support for the R560 series, including driver versions 560.35.03. Added support for the R550 series, including driver versions 550.127.05 and 550.90.12. Assigned the latest, default, and R560 tags to driver version 560.35.03. Assigned the R550 tag to driver version 550.127.05.

Security

Fixed CVE-2024-50140 in the Linux kernel.

Security

Fixed CVE-2024-50278 in the Linux kernel.

Feature

Upgraded cos-gpu-installer to v2.4.6: Support NVIDIA_H200 GPU in cos-gpu-installer

December 04, 2024

Change

cos-117-18613-75-60

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.24 See List
Security

Fixed CVE-2024-53052 in the Linux kernel.

Security

Fixed CVE-2024-50215 in the Linux kernel.

Change

Upgraded containerd from 1.7.23 to 1.7.24.

Security

Fixed CVE-2024-50169 in the Linux kernel.

Security

Fixed CVE-2024-50251 in the Linux kernel.

Security

Fixed CVE-2024-50162 in the Linux kernel.

Security

Fixed CVE-2024-50226 in the Linux kernel.

Security

Fixed CVE-2024-50060 in the Linux kernel.

Security

Fixed CVE-2024-50154 in the Linux kernel.

Security

Fixed CVE-2024-50192 in the Linux kernel.

Security

Fixed CVE-2024-50262 in the Linux kernel.

Security

Fixed CVE-2024-50163 in the Linux kernel.

Security

Fixed CVE-2024-50275 in the Linux kernel.

Security

Fixed CVE-2024-50063 in the Linux kernel.

Security

Fixed CVE-2024-50147 in the Linux kernel.

Fixed

Upgraded cos-gpu-installer to v2.4.4. This fixes an issue where GPU drivers that only have two numeric version components could not be loaded.

Security

Fixed CVE-2024-50182 in the Linux kernel.

Security

Fixed CVE-2024-50223 in the Linux kernel.

Change

Upgraded net-misc/socat to v1.8.0.1.

Change

Upgraded sys-apps/less to v668.

Change

Upgraded sys-process/lsof to v4.99.4.

Security

Fixed CVE-2024-50194 in the Linux kernel.

Security

Fixed CVE-2024-50249 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811800 -> 811804

Security

Fixed CVE-2024-50258 in the Linux kernel.

Security

Fixed CVE-2024-50279 in the Linux kernel.

Security

Fixed CVE-2024-53054 in the Linux kernel.

Change

Upgraded sys-apps/makedumpfile to v1.7.6.

Security

Fixed CVE-2024-50228 in the Linux kernel.

Security

Fixed KCTF-6ca5753 in the Linux kernel.

Security

Fixed CVE-2024-50142 in the Linux kernel.

Security

Fixed CVE-2024-50099 in the Linux kernel.

Change

Upgraded app-shells/dash to v0.5.12-r1.

Change

Updated app-admin/google-guest-configs to 20241121.00. This enables intent based NIC naming scheme.

Security

Fixed CVE-2024-50152 in the Linux kernel.

Security

Fixed CVE-2024-50271 in the Linux kernel.

Security

Updated net-misc/curl to v8.11.0. This fixes CVE-2024-9681. Added duphandle-init-netrc.patch, netrc-large-file.patch, setopt-http_content_decoding.patch to fix regression issues in curl v8.11.0.

Security

Fixed CVE-2024-50257 in the Linux kernel.

Security

Fixed CVE-2024-53042 in the Linux kernel.

Security

Fixed CVE-2024-50222 in the Linux kernel.

Security

Fixed CVE-2024-50153 in the Linux kernel.

Security

Fixed CVE-2024-50272 in the Linux kernel.

Security

Fixed CVE-2024-53082 in the Linux kernel.

Security

Fixed CVE-2024-50143 in the Linux kernel.

Security

Fixed CVE-2024-50151 in the Linux kernel.

Security

Fixed CVE-2024-53066 in the Linux kernel.

Security

Fixed CVE-2024-50195 in the Linux kernel.

Security

Fixed CVE-2024-50141 in the Linux kernel.

November 18, 2024

Change

cos-117-18613-75-37

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.23 See List
Security

Fixed CVE-2024-50115 in the Linux kernel.

Security

Fixed CVE-2024-50130 in the Linux kernel.

Security

Fixed CVE-2024-50010 in the Linux kernel.

Security

Fixed CVE-2024-50120 in the Linux kernel.

Security

Fixed CVE-2024-50121 in the Linux kernel.

Security

Fixed CVE-2024-50101 in the Linux kernel.

Security

Fixed CVE-2024-50095 in the Linux kernel.

Security

Fixed CVE-2024-50110 in the Linux kernel.

Security

Fixed CVE-2024-50131 in the Linux kernel.

Security

Fixed CVE-2024-50066 in the Linux kernel.

November 11, 2024

Change

cos-117-18613-75-26

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.23 See List
Security

Updated runc to version 1.1.14. This fixes CVE-2024-45310, CVE-2024-9341, CVE-2024-9407, and CVE-2024-9675

Security

Fixed CVE-2024-50076 in the Linux kernel.

Security

Fixed CVE-2024-50036 in the Linux kernel.

Security

Fixed CVE-2024-50067 in the Linux kernel.

Security

Fixed KCTF-2e95c43 in the Linux kernel.

Security

Fixed CVE-2024-50602 in dev-libs/expat.

Security

Fixed CVE-2024-50038 in the Linux kernel.

Security

Fixed CVE-2024-50024 in the Linux kernel.

Security

Fixed CVE-2024-50072 in the Linux kernel.

Security

Fixed KCTF-8ea6073 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811757 -> 811721

Security

Fixed CVE-2024-50082 in the Linux kernel.

November 06, 2024

Change

cos-117-18613-75-7

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.23 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811796 -> 811757

Change

Upgraded sys-apps/xemu to v0.0.6

October 31, 2024

Change

cos-117-18613-75-4

Kernel Docker Containerd GPU Drivers
COS-6.6.56 v24.0.9 v1.7.23 See List
Announcement
Security

Fixed CVE-2024-47739 in the Linux kernel.

Security

Fixed CVE-2024-47706 in the Linux kernel.

Security

Fixed CVE-2024-47700 in the Linux kernel.

Security

Fixed CVE-2024-47682 in the Linux kernel.

Security

Fixed CVE-2024-50019 in the Linux kernel.

Security

Fixed CVE-2024-50039 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811706 -> 811796

Security

Fixed CVE-2024-47692 in the Linux kernel.

Security

Fixed CVE-2024-47688 in the Linux kernel.

Security

Fixed CVE-2024-49975 in the Linux kernel.

Security

Fixed CVE-2024-49889 in the Linux kernel.

Security

Fixed CVE-2024-50046 in the Linux kernel.

Security

Fixed CVE-2024-47728 in the Linux kernel.

Security

Fixed CVE-2024-50015 in the Linux kernel.

Security

Fixed CVE-2024-50035 in the Linux kernel.

Security

Fixed CVE-2024-50055 in the Linux kernel.

Security

Fixed CVE-2024-50045 in the Linux kernel.

Security

Fixed CVE-2024-50033 in the Linux kernel.

Security

Fixed CVE-2024-49860 in the Linux kernel.

Security

Fixed CVE-2024-47727 in the Linux kernel.

Security

Fixed CVE-2024-49851 in the Linux kernel.

Security

Fixed CVE-2024-50058 in the Linux kernel.

Security

Fixed CVE-2024-47701 in the Linux kernel.

Security

Fixed CVE-2024-50023 in the Linux kernel.

Security

Fixed CVE-2024-47684 in the Linux kernel.

Security

Fixed CVE-2024-47744 in the Linux kernel.

Security

Fixed CVE-2024-47737 in the Linux kernel.

Security

Fixed CVE-2024-50000 in the Linux kernel.

Security

Fixed CVE-2024-47745 in the Linux kernel.

Security

Fixed CVE-2024-47660 in the Linux kernel.

Security

Fixed CVE-2024-49850 in the Linux kernel.

Security

Fixed CVE-2024-47696 in the Linux kernel.

Feature

Added NVIDIA GPU drivers R560 branch - Update R560, latest driver to v560.35.03.

Security

Update NVIDIA GPU drivers to v535.216.01 for default/R535 and v550.127.05 for R550 for all GPUs. This resolves CVE-2024-0126.

Security

Fixed CVE-2024-47743 in the Linux kernel.

Security

Fixed CVE-2024-50064 in the Linux kernel.

Security

Fixed CVE-2024-49858 in the Linux kernel.

Security

Fixed CVE-2024-47734 in the Linux kernel.

Security

Fixed CVE-2024-47742 in the Linux kernel.

Security

Fixed CVE-2024-50047 in the Linux kernel.

Security

Fixed CVE-2024-47668 in the Linux kernel.

Security

Fixed CVE-2024-47693 in the Linux kernel.

Security

Fixed CVE-2024-47679 in the Linux kernel.

Security

Fixed CVE-2024-49936 in the Linux kernel.

Feature

Update R550, latest driver to v550.90.12.

Security

Fixed CVE-2024-47678 in the Linux kernel.

Security

Fixed CVE-2024-47675 in the Linux kernel.

October 28, 2024

Change

cos-117-18613-0-99

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.23 See List
Security

Fixed CVE-2024-47674 in the Linux kernel.

Security

Fixed CVE-2024-44991 in the Linux kernel.

Security

Fixed CVE-2024-47685 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811768 -> 811706

October 21, 2024

Change

cos-117-18613-0-92

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.23 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811790 -> 811768

Security

Fixed CVE-2024-46838 in the Linux kernel.

Security

Fixed CVE-2024-44959 in the Linux kernel.

Security

Fixed KCTF-32556ce in the Linux kernel.

Security

Fixed CVE-2024-45003 in the Linux kernel.

Security

Updated app-arch/libarchive to version 3.7.6. This fixed CVE-2024-48957, CVE-2024-48958.

Security

Fixed CVE-2024-44958 in the Linux kernel.

Change

Updated app-containers/containerd to 1.7.23.

October 14, 2024

Change

cos-117-18613-0-79

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.22 See List
Security

Fixed CVE-2024-46829 in the Linux kernel.

Security

Fixed CVE-2024-44970 in the Linux kernel.

Security

Fixed CVE-2024-46848 in the Linux kernel.

Security

Fixed CVE-2024-46847 in the Linux kernel.

Security

Fixed CVE-2024-46855 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811772 -> 811790

Security

Fixed CVE-2024-46864 in the Linux kernel.

Security

Fixed CVE-2024-44965 in the Linux kernel.

October 07, 2024

Change

cos-117-18613-0-76

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.22 See List
Security

Upgraded to v1.16.2. Fixed CVE-2024-0132 and CVE-2024-0133.

Feature

Update R535, default driver to v535.183.06.

Security

Fixed CVE-2024-46750 in the Linux kernel.

Security

Fixed CVE-2024-46786 in the Linux kernel.

Fixed

Disabled MGLRU by default due to integration issues with Kubernetes.

Security

Fixed CVE-2024-46744 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811758 -> 811772

October 02, 2024

Change

cos-117-18613-0-66

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.22 See List
Announcement

Promoted M117 to stable.

September 30, 2024

Change

cos-beta-117-18613-0-66

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.22 See List
Security

Fixed CVE-2024-46796 in the Linux kernel

Security

Fixed CVE-2024-46721 in the Linux kernel

Security

Fixed CVE-2024-46738 in the Linux kernel

Feature

Fixed A3 Edge VM names in google guest agent configs and upgrade to v20240725.

Security

Fixed CVE-2024-46763 in the Linux kernel.

Security

Fixed CVE-2024-46762 in the Linux kernel.

Security

Fixed CVE-2024-46737 in the Linux kernel

Security

Fixed CVE-2024-46800 in the Linux kernel

Security

Fixed CVE-2024-46743 in the Linux kernel

Security

Fixed CVE-2024-46679 in the Linux kernel.

September 23, 2024

Change

cos-beta-117-18613-0-57

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.22 See List
Fixed

Updated net-misc/curl to 8.10.0.

Security

Fixed CVE-2024-46686 in the Linux kernel

Security

Fixed CVE-2024-45021 in the Linux kernel

Security

Fixed CVE-2024-45020 in the Linux kernel

Change

Upgraded app-admin/fluent-bit to v3.1.8.

Security

Fixed CVE-2024-45022 in the Linux kernel

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811711 -> 811780

Security

Fixed CVE-2024-44947 in the Linux kernel

Security

Fixed CVE-2024-44940 in the Linux kernel

Security

Fixed CVE-2024-44983 in the Linux kernel

Security

Fixed CVE-2024-45025 in the Linux kernel

Feature

Updated cos-gpu-installer to v2.4.2. This enables creation of /dev/dri when loading nvidia-drm.ko for COS kernels build with loadable drm and dependent modules.

Security

Fixed CVE-2024-44996 in the Linux kernel

Security

Fixed CVE-2024-45018 in the Linux kernel

September 16, 2024

Change

cos-beta-117-18613-0-41

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.22 See List
Security

Updated dev-lang/python to v3.8.19_p1. This fixes CVE-2007-4559.

Security

Updated dev-libs/expat to version v2.6.3. This fixed CVE-2024-45492, CVE-2024-45490, CVE-2024-45491.

Security

Fixed CVE-2024-44985 in the Linux kernel

Security

Fixed CVE-2024-44943 in the Linux kernel

Security

Fixed CVE-2023-27043 in dev-lang/python.

Security

Fixed CVE-2024-6119 in net-libs/openssl.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811784 -> 811711

Security

Fixed CVE-2024-45000 in the Linux kernel

Security

Fixed CVE-2024-7592 in dev-lang/python.

Security

Fixed CVE-2024-43891 in the Linux kernel

Security

Fixed CVE-2024-43892 in the Linux kernel

Security

Fixed CVE-2024-6232 in dev-lang/python.

Security

Fixed CVE-2024-43914 in the Linux kernel

Security

Fixed CVE-2024-43882 in the Linux kernel

Security

Fixed CVE-2024-43893 in the Linux kernel

Security

Fixed CVE-2023-7256 in net-libs/libpcap.

Security

Fixed CVE-2024-44952 in the Linux kernel

Security

Fixed CVE-2024-44987 in the Linux kernel

Security

Fixed CVE-2024-44957 in the Linux kernel

Security

Fixed CVE-2024-44989 in the Linux kernel

Change

Updated app-containers/containerd to v1.7.22.

Security

Fixed CVE-2024-44990 in the Linux kernel

Security

Fixed CVE-2024-44986 in the Linux kernel

September 09, 2024

Change

cos-beta-117-18613-0-25

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.21 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811778 -> 811784

Security

Fixes CVE-2024-43889 in the Linux kernel.

September 03, 2024

Change

cos-beta-117-18613-0-24

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.21 See List
Security

Fixed CVE-2024-37370, CVE-2024-37371 in app-crypt/mit-krb5.

Security

Updated app-editors/vim, app-editors/vim-core to version 9.1.0686. This fixed CVE-2024-41957, CVE-2024-41965.

Security

Fixed CVE-2024-42269 in the Linux kernel.

Security

Fixed CVE-2024-42268 in the Linux kernel.

Security

Fixed CVE-2024-44934 in the Linux kernel.

Security

Fixed CVE-2024-42270 in the Linux kernel.

Security

Fixed KCTF-c07ff85 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811697 -> 811778
  • Changed: net.ipv4.tcp_rto_min_us: 200000 -> 5000

Change

Updated app-containers/containerd to 1.7.21.

August 26, 2024

Change

cos-beta-117-18613-0-10

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.20 See List
Fixed

Updated google-osconfig-agent to v20240822.00.

Change

Upgraded app-admin/fluent-bit to v3.1.6.

Change

Upgraded sys-apps/pv to v1.8.12.

August 20, 2024

Change

cos-beta-117-18613-0-3

Kernel Docker Containerd GPU Drivers
COS-6.6.44 v24.0.9 v1.7.20 See List
Change

Updated toolbox to v20230714.

Fixed

Allow GPU driver installation on dev-channel images without the -test flag.

Security

Fixed CVE-2024-34459 in the libxml2 package.

Feature

Mount efivarfs fs by default on EFI-enabled systems.

Change

Upgraded sys-apps/makedumpfile to v1.7.5.

Feature

Added support for iSCSI targets and RAM block devices.

Change

Upgraded app-benchmarks/bootchart to v0.9.2-r5.

Security

Updated dev-libs/expat to version 2.6.2. This fixed CVE-2024-28757.

Change

Updated app-containers/nvidia-container-toolkit to v1.14.6.

Security

Upgraded dev-lang/go to v1.22.4. This fixes CVE-2023-39323, CVE-2023-44487, CVE-2023-39325, CVE-2024-24790 and CVE-2024-24789.

Security

Fixed CVE-2023-40546, CVE-2023-40548, CVE-2023-40549 and CVE-2023-40550 in sys-boot/shim.

Security

Upgraded dev-go/crypto to v0.17.0. This fixes CVE-2023-48795.

Security

Fixed CVE-2023-4016 in sys-process/procps.

Change

Upgraded sys-libs/libseccomp to v2.5.5-r1.

Change

Upgraded chromeos-base/google-breakpad to v2024.01.16.190249-r226.

Announcement

Updates to Major Packages:

Security

Upgraded app-arch/libarchive to version 3.7.4. Fixes CVE-2024-26256.

Change

Upgraded sys-apps/hwdata to v0.383.

Change

Upgraded sys-apps/dbus to v1.14.10-r192. This fixes CVE-2023-34969.

Fixed

Disable NVIDIA persistence mode with -no-verify flag

Change

Upgraded sys-apps/sed to v4.9-r1.

Feature

Removed net-libs/grpc.

Security

Upgraded sys-fs/mdadm to v4.2. This resolves CVE-2023-28938 and CVE-2023-28736.

Change

Upgraded sys-apps/gentoo-functions to v1.6.

Security

Updated net-misc/curl to version 8.9.1. This fixed CVE-2024-2004, CVE-2024-2379, CVE-2024-2398, CVE-2024-2466, CVE-2023-38545, CVE-2024-7264, CVE-2024-6197.

Announcement

CVE/Security Fixes:

Change

Upgraded dev-python/jinja to v3.1.4.

Change

Upgraded dev-python/pygobject to v3.46.0-r1.

Change

Upgraded net-misc/chrony to v4.5.

Feature

Enabled the feature to utilize the gpu_driver_versions proto file for controlling the specific GPU driver version to be installed for each GPU type.

Feature

Removed deprecated R525 NVIDIA GPU drivers.

Fixed

Installed the google_optimize_local_ssd script.

Change

Upgraded sys-apps/rootdev to v0.0.1-r50.

Change

Updated docker-credential-gcr to v2.1.22.

Security

Fixed CVE-2023-40547 in sys-boot/shim.

Change

Upgraded net-libs/libtirpc to v1.3.4-r2.

Change

Upgraded sys-process/procps to v4.0.4-r1.

Change

Upgraded net-misc/wget to v1.24.5.

Change

Upgraded dev-db/sqlite to v3.46.0.

Feature

Removed crash-reporter KVM support.

Feature

Removed dev-go/grpc.

Fixed

Fixed glibc-2.36 build errors in sys-boot/syslinux.

Security

Fixed CVE-2024-0684 in sys-apps/coreutils.

Change

Upgraded sys-apps/grep to v3.11-r1.

Security

Fixed CVE-2024-28182 in net-libs/nghttp2.

Security

Updated dev-libs/openssl to v3.0.14. This resolves CVE-2024-0727, CVE-2023-6129, CVE-2024-2511, CVE-2024-4603, CVE-2024-4741 and CVE-2024-5535.

Change

Upgraded sys-libs/timezone-data to v2024a-r1.

Security

Updated app-editors/vim, app-editors/vim-core to v9.0.2092. This resolves CVE-2023-4733, CVE-2023-4734, CVE-2023-4735, CVE-2023-4736, CVE-2023-4738, CVE-2023-4750, CVE-2023-4752, CVE-2023-4781, CVE-2023-5344, CVE-2023-5441, CVE-2023-5535, CVE-2023-2609, CVE-2023-2610, CVE-2023-2426.

Change

Upgraded chromeos-base/minijail to v18-r142.

Change

Upgraded app-emulation/cloud-init to v23.4.3.

Change

Upgraded app-admin/google-guest-agent to v20240716.00.

Fixed

Updated dev-go/term to v0.15.0.

Announcement

New Features and Changes in the Image:

Security

Upgraded docker to v24.0.9. This fixes CVE-2024-24557.

Change

Updated app-emulation/kubernetes to v1.30.3.

Change

Upgraded net-libs/gnutls to v3.8.6.

Change

Upgraded chromeos-base/session_manager-client to v0.0.1-r2796.

Fixed

Updated NVIDIA GPU drivers to v535.161.08. Fixed a potential corruption when launching kernels on H100 GPUs.

Change

Upgraded sys-apps/less to v661.

Change

Upgraded dev-util/puffin to v1.0.0-r451.

Security

Fixed CVE-2024-39894 in net-misc/openssh.

Change

Added support for TPU v6 devices.

Security

Updated R550, latest driver to v550.90.07. This fixes CVE-2024-0090, CVE-2024-0091 and CVE-2024-0092.

Change

Upgraded chromeos-base/system_api to v0.0.1-r5653.

Announcement

Updates for Minor Packages:

Change

Upgraded net-dns/c-ares to v1.31.0.

Change

Upgraded chromeos-base/dlcservice-client to v0.0.1-r886.

Security

Update dev-go/protobuf to v1.33.0. This fixes CVE-2024-24786.

Change

Upgraded dev-libs/nss to v3.97.

Change

Upgraded chromeos-base/hiberman-client to v0.0.1-r470.

Security

Updated dev-go/net to v0.27.0. This resolves CVE-2023-44487, CVE-2023-39325 and CVE-2023-45288.

Change

Upgraded localtoast to v1.1.7 and opted out of logging-service-running benchmark by default for cis-level2.

Change

Upgraded app-containers/docker, app-containers/docker-test and app-containers/docker-cli to v24.0.9.

Security

Fixed CVE-2021-36084, CVE-2021-36085, CVE-2021-36086, CVE-2021-36087 in sys-libs/libsepol.

Change

Updated sys-apps/systemd to v254.9.

Fixed

Updated dev-go/go-tools to v0.16.2_p20231218.

Change

Upgraded chromeos-base/chromeos-dbus-bindings to v0.0.1-r2795.

Change

Upgraded app-admin/fluent-bit to v3.1.3.

Feature

Disabled default automatic updates. Automatic updates must now be explicitly enabled by setting the cos-update-strategy metadata to "update_enabled".

Announcement

New Features and Changes in the Linux Kernel:

Security

Updated dev-vcs/git to version VERSION. This fixed CVE-2023-22490, CVE-2023-23946, CVE-2023-25652, CVE-2023-25815, CVE-2023-29007.

Change

Upgraded sys-libs/libcap to v2.70.

Security

Updated dev-python/setuptools to v70.3.0. This resolves CVE-2024-6345.

Security

Fixed CVE-2023-5388 in dev-libs/nss.

Change

Upgraded app-admin/google-guest-configs to v20240607.00.

Fixed

Upgraded Konlet to v.0.12.0. This fixes an iptables compatibility issue.

Feature

Fragmented nvidia-drivers and nvidia-drivers-open pkg into separate packages per major version.

Security

Fixed CVE-2024-39472 in the linux kernel.

Fixed

Fixed a time-to-login slowdown introduced by cloud-init changes.

Security

Updated dev-python/pyyaml to version 6.0.1. This fixed CVE-2017-18342, CVE-2020-14343, CVE-2020-1747.

Feature

Changed default umask value for a user to 027.

Change

Upgraded app-arch/xz-utils to v5.4.6-r1.

Fixed

Upgraded sys-apps/coreutils to v9.3-r1.

Change

Upgraded sys-apps/ethtool to v6.9.

Change

Upgraded chromeos-base/update_engine-client to v0.0.1-r2441.

Fixed

Updated dev-go/sync to v0.5.0.

Feature

Added support for dm-zero and dm-clone.

Feature

Enabled support for MGLRU in the Linux kernel.

Feature

Removed support for NVIDIA 470 drivers.

Fixed

Fixed a bug in google-guest-agent service enablement.

Change

Upgraded chromeos-base/chromeos-common-script to v0.0.1-r637.

Security

Fixed CVE-2023-50387, CVE-2023-50868 in sys-apps/systemd.

Fixed

Updated dev-go/pprof to v0.0.0_p20230811.

Change

Upgraded app-admin/google-osconfig-agent to v20240501.00.

Security

Fixed CVE-2024-23851 in the Linux kernel.

Feature

Removed legacy logging agent (fluentd).

Change

Upgraded sys-auth/pambase to v20240128.

Change

Upgraded sys-fs/xfsprogs to v6.8.0.

Feature

Updated cos-gpu-installer to v2.3.5.

Security

Updated dev-libs/libxml2 to 2.11.7. This fixes CVE-2024-25062.

Security

Fixed CVE-2024-35195 in dev-python/requests.

Change

Updated app-containers/runc to v1.1.12.

Security

Updated dev-vcs/git to v2.45.1. This resolves CVE-2024-32002,CVE-2024-32020,CVE-2024-32465,CVE-2024-32004,CVE-2024-32021.

Fixed

Updated NVIDIA GPU drivers to v550.54.15. Fixed a potential corruption when launching kernels on H100 GPUs, which is more likely to occur when the GPU is shared between multiple processes.

Change

Upgraded app-containers/cni-plugins to v1.5.1.

Change

Upgraded sys-fs/e2fsprogs to v1.47.0-r3.

Change

Upgraded sys-apps/sandbox to v2.29-r1.

Fixed

Fixed bug that cause constant restarts in fluent-bit stackdriver plugin.

Security

Fixed CVE-2023-0687, CVE-2024-2961, CVE-2024-33599, CVE-2024-33600, CVE-2024-33601, CVE-2024-33602 in sys-libs/glibc.

Security

Fixed CVE-2023-4641 in sys-apps/shadow.

Change

Upgraded chromeos-base/vm_protos to v0.0.1-r563.

Security

Updated R535, default driver to v535.183.01. This fixes CVE-2024-0090 and CVE-2024-0092.

Security

Updated net-libs/nghttp2 to v1.57.0. This resolves CVE-2023-44487 and CVE-2023-35945.

Fixed

Updated net-misc/openssh to v9.6_p1-r1.

Change

Downgraded app-misc/ca-certificates to v20230311.3.96.1.

Fixed

Upgraded dev-util/bsdiff to v4.3.1-r42.

Feature

Added igzip CLI tool.

Change

Upgraded net-misc/rsync to v3.3.0-r1.

Feature

Added more service logs to the default Cloud Logging configuration.

Change

Upgraded app-containers/docker-credential-helpers to v0.8.2.

Fixed

Upgraded go to version 1.22.3.

Change

Runtime sysctl changes:

  • Added: dev.tty.legacy_tiocsti: 1
  • Added: kernel.io_uring_group: -1
  • Added: kernel.kexec_load_limit_panic: -1
  • Added: kernel.kexec_load_limit_reboot: -1
  • Added: kernel.loadpin.enforce: 1
  • Added: net.core.mem_pcpu_rsv: 256
  • Added: net.core.rps_default_mask: 00
  • Added: net.ipv4.tcp_plb_cong_thresh: 128
  • Added: net.ipv4.tcp_plb_enabled: 0
  • Added: net.ipv4.tcp_plb_idle_rehash_rounds: 3
  • Added: net.ipv4.tcp_plb_rehash_rounds: 12
  • Added: net.ipv4.tcp_plb_suspend_rto_sec: 60
  • Added: net.ipv4.tcp_rto_min_us: 200000
  • Added: net.ipv4.tcp_shrink_window: 0
  • Added: net.ipv4.tcp_syn_linear_timeouts: 4
  • Added: net.ipv4.udp_child_hash_entries: 0
  • Added: net.ipv4.udp_hash_entries: 4096
  • Added: net.ipv6.conf.all.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.default.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.docker0.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.eth0.accept_ra_min_lft: 0
  • Added: net.ipv6.conf.lo.accept_ra_min_lft: 0
  • Added: net.ipv6.icmp.error_anycast_as_unicast: 0
  • Added: vm.memfd_noexec: 0
  • Added: kernel.io_uring_disabled: 0
  • Added: fs.overflowgid: 65534
  • Changed: net.core.optmem_max: 131072 -> 20480
  • Changed: vm.lowmem_reserve_ratio: 256 256 32 0 0 -> 256 256 32 0
  • Changed: fs.epoll.max_user_watches: 1809452 -> 1809007
  • Changed: fs.fanotify.max_user_marks: 67560 -> 67544
  • Changed: fs.file-max: 811776 -> 811724
  • Changed: fs.inotify.max_user_watches: 63441 -> 63425
  • Changed: kernel.threads-max: 63503 -> 63487
  • Changed: net.ipv4.tcp_mem: 94065 125423 188130 -> 94041 125391 188082
  • Changed: net.ipv4.udp_mem: 188133 250847 376266 -> 188085 250783 376170
  • Changed: user.max_cgroup_namespaces: 31751 -> 31743
  • Changed: user.max_fanotify_marks: 67560 -> 67544
  • Changed: user.max_inotify_watches: 63441 -> 63425
  • Changed: user.max_ipc_namespaces: 31751 -> 31743
  • Changed: user.max_mnt_namespaces: 31751 -> 31743
  • Changed: user.max_net_namespaces: 31751 -> 31743
  • Changed: user.max_pid_namespaces: 31751 -> 31743
  • Changed: user.max_time_namespaces: 31751 -> 31743
  • Changed: user.max_user_namespaces: 31751 -> 31743
  • Changed: user.max_uts_namespaces: 31751 -> 31743
  • Changed: net.ipv6.route.max_size: 4096 -> 2147483647
  • Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_recd: 0 -> 3
  • Changed: net.netfilter.nf_conntrack_sctp_timeout_shutdown_sent: 0 -> 3

Change

Upgraded dev-embedded/libftdi to v1.5-r7.

Change

Upgraded chromeos-base/shill-client to v0.0.1-r4612.

Feature

Enhanced integrity-fs with disk resize and dm-clone.

Fixed

Enabled vrf, ip_gre, and ip6_gre modules.

Change

Upgraded dev-libs/libusb to v1.0.27-r1.

Change

Upgraded sys-apps/pv to v1.8.10.

Change

Upgraded sys-libs/libcap-ng to v0.8.5.

Fixed

Updated dev-go/go-sys to v0.15.0.

Feature

Fixed integrity-fs dm-crypt creation flakiness.

Change

Updated the Linux kernel to v6.6.44.

Security

Fixed CVE-2023-32681 in dev-python/requests.

Change

Upgraded dev-libs/double-conversion to v3.3.0.

Change

Upgraded sys-apps/acl to v2.3.2-r1.

Change

Upgraded chromeos-base/debugd-client to v0.0.1-r2707.

Change

Upgraded app-admin/node-problem-detector to v0.8.19.

Feature

Included nvidia plugin into sosreport.

Fixed

Updated dev-go/go-arch to v0.6.0.

Security

Fixed CVE-2024-3772 in dev-python/pydantic.

Change

Upgraded sys-apps/dmidecode to v3.6.

Change

Upgraded app-admin/logrotate to v3.22.0.

Feature

Added automatic generation of known modules list to image build process.

Feature

Added NVIDIA GPU drivers R550 branch and updated latest to 550.54.14.

Security

Fixed CVE-2024-21626 in github.com/opencontainers/runc in kubelet.

Change

Upgraded sys-apps/findutils to v4.10.0.

Feature

Added the package revision number to the SSH banner in net-misc/openssh.

Fixed

Updated dev-go/demangle to v0.0.0_p20230524.

Change

Upgraded chromeos-base/power_manager-client to v0.0.1-r2942.

Security

Fixed CVE-2023-40551 in sys-boot/shim.

Change

Upgraded app-admin/sosreport to v4.7.1.

Change

Upgraded sys-fs/squashfs-tools to v4.6.1.

Security

Upgraded app-arch/lz4 to 1.9.4. Fixes CVE-2021-3520.

Change

Upgraded sys-block/thin-provisioning-tools to v0.9.0-r4.

Fixed

Updated dev-go/mod to v0.14.0.

Fixed

Upgraded app-arch/pigz to v2.8.

Change

Upgraded sys-boot/grub-lakitu to the FC 39's current version.

Security

Fixed CVE-2023-1255 in the dev-libs/openssl package.

Security

Fixed CVE-2024-21626 in app-containers/runc.

Change

Upgraded sys-libs/gdbm to v1.24.

Fixed

Upgraded dev-python/netifaces to v0.11.0-r2.

Change

Upgraded sys-libs/timezone-data to v2024a.

Fixed

Updated protobuf-legacy-api to v1.5.4.

Change

Updated gzip to v1.13-r1.

Change

Upgraded sys-libs/zlib to v1.3.1-r1.

Change

Upgraded net-dns/libidn2 to v2.3.7.

Fixed

Upgraded sys-libs/libcap-ng to v0.8.4-r1.

Change

Upgraded sys-apps/attr to v2.5.2-r1.

Change

Upgraded sys-apps/file to v5.45-r4.

Fixed

Upgraded app-eselect/eselect-iptables to v20220320.