Container-Optimized OS Release Notes: Milestone 125

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

November 17, 2025

Change

cos-125-19216-104-25

Kernel Docker Containerd GPU Drivers
COS-6.12.55 v27.5.1 v2.1.4 See List
Fixed

Backported various TCPDirect networking fixes.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811458 -> 811512

November 14, 2025

Change

cos-125-19216-104-23

Kernel Docker Containerd GPU Drivers
COS-6.12.55 v27.5.1 v2.1.4 See List
Change

Updated app-containers/runc to v1.3.3.

Fixed

Fixed a bug where setting MTU above 9000 on ARM systems with a 64k page size would cause IDPF networking to fail.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811489 -> 811458

November 11, 2025

Change

cos-125-19216-104-17

Kernel Docker Containerd GPU Drivers
COS-6.12.55 v27.5.1 v2.1.4 See List
Fixed

Enabled multiport support for CX-8 devices.

Security

Fixed CVE-2025-40083 in the Linux kernel.

Feature

Added support for the Lustre 2.14.0_p224 drivers.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811455 -> 811489
  • Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068

Fixed

Upgraded sys-apps/makedumpfile to v1.7.8.

Feature

Enabled HTCP TCP congestion control algorithm as a module.

Fixed

Fixed a race condition where unmounting file systems monitored by inotify or fanotify could result in kernel crash.

Change

Updated app-containers/containerd to v2.1.4.

Security

Fixed CVE-2025-21833 in the Linux kernel.

Feature

Added support for SCSI logging.

Fixed

Made CX-8 NIC naming order deterministic.

November 07, 2025

Change

cos-125-19216-104-5

Kernel Docker Containerd GPU Drivers
COS-6.12.55 v27.5.1 v2.1.3 See List
Fixed

Fixed bcache latency spikes.

Security

Fixed CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 in app-containers/runc.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811499 -> 811455

November 03, 2025

Change

cos-125-19216-104-3

Kernel Docker Containerd GPU Drivers
COS-6.12.55 v27.5.1 v2.1.3 See List
Security

Fixed CVE-2025-40009 in the Linux kernel.

Fixed

Fixed a TCPX bug which would sometimes incorrectly report devices as being missing when route cache entries were missing or invalidated.

Feature

Fixed a bug in cos-extensions which would cause GB200 and GB300 devices not to be detected in one code path, which would result in Imex channels not being created by default.

Security

Fixed CVE-2025-40006 in the Linux kernel.

Announcement

This is an LTS refresh release.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811500 -> 811499
  • Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068

Fixed

Upgraded dev-lang/go to v1.23.12.

October 27, 2025

Change

cos-125-19216-0-115

Kernel Docker Containerd GPU Drivers
COS-6.12.46 v27.5.1 v2.1.3 See List
Fixed

Upgraded sys-apps/pv to v1.9.44.

Security

Fixed CVE-2025-11413, CVE-2025-11414 in binutils-libs.

Change

Updated cos-gpu-installer to v2.5.9. This adds support for installing drivers for GB 300 devices.

Fixed

Added support for NVIDIA driver v535.274.02 and v570.195.03.

Feature

Added GB300 support to cos-extensions.

October 24, 2025

Change

cos-125-19216-0-110

Kernel Docker Containerd GPU Drivers
COS-6.12.46 v27.5.1 v2.1.3 See List
Change

Added support for A4X-Max NICs.

Fixed

Upgraded sys-apps/hwdata to v0.400.

Fixed

Upgraded sys-apps/less to v685.

Fixed

Reduced gcr_wait_online retry gap.

Feature

Added support for NVIDIA GB300 devices.

Security

Fixed CVE-2025-11412 in binutils-libs.

Change

Updated cos-gpu-installer to v2.5.8.

Fixed

Upgraded sys-apps/pv to v1.9.42.

Security

Fixed CVE-2025-11494 in binutils-libs.

Change

Updated app-containers/runc to v1.2.7.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068

Security

Fixed CVE-2025-11495 in binutils-libs.

October 20, 2025

Change

cos-125-19216-0-100

Kernel Docker Containerd GPU Drivers
COS-6.12.46 v27.5.1 v2.1.3 See List
Security

Fixed CVE-2025-39992 in the Linux kernel.

Security

Fixed CVE-2025-39977 in the Linux kernel.

Security

Fixed CVE-2025-39980 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811534 -> 811421
  • Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068

Security

Fixed CVE-2025-39973 in the Linux kernel.

Security

Fixed CVE-2025-39990 in the Linux kernel.

Security

Fixed CVE-2025-38322 in the Linux kernel.

Security

Fixed CVE-2025-39940 in the Linux kernel.

Security

Fixed CVE-2025-39969 in the Linux kernel.

Security

Fixed CVE-2025-39972 in the Linux kernel.

Security

Fixed CVE-2025-39971 in the Linux kernel.

Security

Fixed CVE-2025-39975 in the Linux kernel.

Security

Fixed CVE-2025-39998 in the Linux kernel.

Security

Fixed CVE-2025-39984 in the Linux kernel.

October 17, 2025

Change

cos-125-19216-0-94

Kernel Docker Containerd GPU Drivers
COS-6.12.46 v27.5.1 v2.1.3 See List
Security

Fixed CVE-2025-39961 in the Linux kernel.

Security

Fixed CVE-2025-41244 in app-emulation/open-vm-tools.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811514 -> 811534
  • Changed: net.ipv4.udp_mem: 188034 250714 376068 -> 188034 250715 376068

Security

Fixed CVE-2025-39965 in the Linux kernel.

Security

Fixed CVE-2025-39963 in the Linux kernel.

Fixed

Updated the dump capture kernel to v6.12.52.

Security

Fixed KCTF-6bb73db in the Linux Kernel.

Fixed

Updated golang.org/x/crypto, golang.org/x/net, and golang.org/x/oauth2 in kubelet and kubectl.

Fixed

Added task information collection to sosreports.

October 13, 2025

Change

cos-125-19216-0-87

Kernel Docker Containerd GPU Drivers
COS-6.12.46 v27.5.1 v2.1.3 See List
Fixed

Partially fixed an issue where excessive contention among writeback kworkers when switching a large number of inodes between cgroups could lead to system unresponsiveness.

Security

Fixed CVE-2025-39931 in the Linux kernel.

Security

Fixed CVE-2025-11081, CVE-2025-11082 and CVE-2025-11083 in sys-libs/binutils-libs.

Fixed

Upgraded app-admin/node-problem-detector to v0.8.22.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811500 -> 811514

Security

Fixed CVE-2025-39953 in the Linux kernel.

Security

Fixed CVE-2025-39947 in the Linux kernel.

Feature

Added support for NVIDIA driver v580.95.05. Updated all latest driver version and default driver versions for NVIDIA_GB200 and NVIDIA_B200 to v580.95.05.

Fixed

Upgraded sys-apps/hwdata to v0.399.

October 09, 2025

Change

cos-125-19216-0-80

Kernel Docker Containerd GPU Drivers
COS-6.12.46 v27.5.1 v2.1.3 See List
Change

Updated toolbox container image tag to v20251002.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811450 -> 811500
  • Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068

Announcement

Promoted Milestone 125 to stable.

Security

Fixed KCTF-134121b in the Linux kernel.

October 06, 2025

Change

cos-beta-125-19216-0-76

Kernel Docker Containerd GPU Drivers
COS-6.12.46 v27.5.1 v2.1.3 See List
Security

Updated dev-python/urllib3 to v1.26.18 and fixed CVE-2025-50181.

Security

Fixed CVE-2025-39926 in the Linux kernel.

Security

Updated dev-python/jinja to v3.1.6. This resolves CVE-2024-56326, CVE-2024-56201 and CVE-2025-27516.

Security

Fixed CVE-2025-39911 in the Linux kernel.

Security

Fixed CVE-2025-39886 in the Linux kernel.

Feature

Configured the cos-gpu-installer to use R580 drivers as the default GPU drivers.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811504 -> 811450

Security

Fixed CVE-2025-39914 in the Linux kernel.

Security

Fixed CVE-2025-22106 in the Linux kernel.

Security

Fixed CVE-2025-39913 in the Linux kernel.

Security

Fixed CVE-2025-39917 in the Linux kernel.

Fixed

Add support for NVIDIA MFT Tools v4.33.0.

Security

Fixed KCTF-1b34cbb in the Linux kernel.

September 29, 2025

Change

cos-beta-125-19216-0-62

Kernel Docker Containerd GPU Drivers
COS-6.12.46 v27.5.1 v2.1.3 See List
Security

Fixed CVE-2025-39882 in the Linux kernel.

Security

Fixed CVE-2025-39884 in the Linux kernel.

Security

Fixed KCTF-0aeb54a in the Linux Kernel.

Fixed

Updated app-admin/node-problem-detector to v0.8.21.

Fixed

Updated golang.org/x/oauth2, golang.org/x/net, golang.org/x/crypto, and github.com/golang-jwt/jwt/v5 in Docker.

Security

Fixed CVE-2025-39881 in the Linux kernel.

Security

Fixed CVE-2025-39883 in the Linux kernel.

Security

Fixed CVE-2025-40300 in the Linux kernel.

September 24, 2025

Change

cos-beta-125-19216-0-53

Kernel Docker Containerd GPU Drivers
COS-6.12.46 v27.5.1 v2.1.3 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811500 -> 811534

Security

Upgraded dev-libs/libxml2 to version 2.13.9. This fixes CVE-2025-9714.

Fixed

Updated the Linux kernel to v6.12.46.

Fixed

Upgraded dev-libs/libxslt to version 1.1.43-r1.

Change

Updated cos-gpu-installer to v2.5.7.

Feature

Added support for the fwctl subsystem and the Mellanox fwctl driver for ARM64.

Change

Enabled Coherent Driver Memory Management by default when installing GPU drivers on GB2000.

Fixed

Added support for NVIDIA driver v580.82.07. Updated all latest driver version and default driver versions for NVIDIA_GB200 and NVIDIA_B200 to v580.82.07.

September 16, 2025

Fixed

Fixed a kernel bug which caused boot to fail for n4 machine types.

Change

cos-beta-125-19216-0-47

Kernel Docker Containerd GPU Drivers
COS-6.12.41 v27.5.1 v2.1.3 See List
Security

Fixed CVE-2025-38571 in the Linux kernel.

Security

Fixed CVE-2025-38639 in the Linux kernel.

Security

Fixed CVE-2025-38588 in the Linux kernel.

Security

Fixed CVE-2025-38614 in the Linux kernel.

Security

Fixed CVE-2025-38645 in the Linux kernel.

Security

Fixed CVE-2025-38565 in the Linux kernel.

Security

Fixed CVE-2025-38587 in the Linux kernel.

Security

Fixed CVE-2025-38608 in the Linux kernel.

Security

Fixed CVE-2025-38572 in the Linux kernel.

Feature

Added support for NVIDIA MFT Tools on arm64.

Security

Fixed CVE-2025-38568 in the Linux kernel.

Security

Fixed CVE-2025-38622 in the Linux kernel.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811507 -> 811500

Feature

Added GDRCopy kernel module for NVIDIA drivers.

Security

Fixed CVE-2025-38640 in the Linux kernel.

September 08, 2025

Change

cos-beta-125-19216-0-38

Kernel Docker Containerd GPU Drivers
COS-6.12.41 v27.5.1 v2.1.3 See List
Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811504 -> 811507

Fixed

Disabled network management by the google-guest-agent.

Security

Fixed CVE-2025-38676 in the Linux kernel.

Feature

Added NVIDIA GPU driver's R580 branch. Updated the LATEST GPU driver label to version 580.65.06.

September 02, 2025

Change

cos-beta-125-19216-0-33

Kernel Docker Containerd GPU Drivers
COS-6.12.41 v27.5.1 v2.1.3 See List
Security

Fixed KCTF-62708b9 in the Linux kernel.

Security

Fixed KCTF-aba0c94 in the Linux kernel.

Security

Fixed CVE-2025-6052 in dev-libs/glib.

Fixed

Added support for the Lustre 2.14.0_p216 drivers.

Feature

Enabled dynamic vlan configuration for non-primary NICs.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811541 -> 811504

Fixed

Upgraded sys-apps/hwdata to v0.398.

Feature

Added iRDMA support in the Linux kernel.

Security

Fixed KCTF-6db015f in the Linux kernel.

Fixed

Upgraded sys-apps/file to v5.46-r3.

August 25, 2025

Change

cos-beta-125-19216-0-24

Kernel Docker Containerd GPU Drivers
COS-6.12.41 v27.5.1 v2.1.3 See List
Feature

Added TDX RTMR support.

Feature

Added ConnectX-8 RDMA support.

Change

Runtime sysctl changes:

  • Changed: fs.file-max: 811484 -> 811541

Security

Fixed KCTF-abad3d0 in the Linux kernel.

Change

Added kernel support for bare-metal on the NVIDIA Grace platform.

Feature

Removed the cloud-final.service dependency on multi-user.target which could delay cloud-init user-data scripts indefinitely when long-running startup scripts are used.

Fixed

Installed app-misc/c_rehash.

Feature

Added IPv6 support for machines using the IDPF driver.

Fixed

Fixed an issue where cpusets cgroups did not work with cgroup v1 enabled.

Feature

Enabled the google-guest-agent's network management functionality.

Feature

Disabled DNSSEC by default for COS TPU VMs.

August 18, 2025

Change

cos-beta-125-19216-0-12

Kernel Docker Containerd GPU Drivers
COS-6.12.41 v27.5.1 v2.1.3 See List
Feature

Injected IMEX channel char device for GB200 GPUs.

Security

Fix CVE-2025-32414, CVE-2025-32415 in dev-libs/libxml2.

Fixed

Upgraded dev-lang/go to v1.23.11.

Fixed

Upgraded dev-libs/expat to v2.7.1.

Security

Patched openssl to fix CVE-2023-50782 affecting dev-python/crytography.

Security

Fixed CVE-2024-48615 in app-arch/libarchive.

Change

Upgraded app-containers/docker to v27.5.1, Upgraded app-containers/docker-test to v27.5.1, Upgraded app-containers/docker-cli to v27.5.1.

Fixed

Removed an artifact registry ping that would delay multi-user.target indefinitely for machines with no external IP address.

Feature

Fixed an issue in containerd that potentially breaks metric collection.

Fixed

Upgraded dev-db/sqlite to v3.50.3.

Security

Updated systemd to v254.26. This resolves CVE-2025-4598.

Change

Updated cos-gpu-installer to v2.5.5.

Feature

Applied Intel patches to add iRDMA support in the Linux kernel.

Fixed

Upgraded app-admin/sudo to v1.9.17_p2.

Security

Fixed CVE-2025-31498 in net-dns/c-ares.

Fixed

Upgraded chromeos-base/update_engine-client to v0.0.1-r2480.

Change

Updated containerd to v2.1.3.

Change

Updated the default tag of the GPU driver supporting the NVIDIA H200 GPU device to 570.86.15.

Security

Updated apparmor to v3.1.6. This fixes CVE-2016-1585.

Fixed

Upgraded sys-apps/hwdata to v0.391.

Fixed

Upgraded dev-libs/nss to v3.110.

Security

Added support for Nvidia driver version 570.172.08. This fixes CVE-2025-23279.

Fixed

Upgraded chromeos-base/power_manager-client to v0.0.1-r2969.

Feature

Backported support for AMD SEV-SNP SVSM vTPM driver and configfs-tsm addition for extended attestation protocol.

Fixed

Updated dev-python/python-dateutil to v2.9.0.

Fixed

Upgraded sysram to version 6.12-0.

Change

Runtime sysctl changes:

  • Added: kernel.apparmor_restrict_unprivileged_unconfined: 0
  • Added: kernel.core_file_note_size_limit: 4194304
  • Added: kernel.core_sort_vma: 0
  • Added: net.ipv4.fib_multipath_hash_seed: 0
  • Added: net.ipv4.tcp_pingpong_thresh: 1
  • Added: net.ipv6.conf.all.ra_honor_pio_life: 0
  • Added: net.ipv6.conf.all.ra_honor_pio_pflag: 0
  • Added: net.ipv6.conf.all.regen_min_advance: 2
  • Added: net.ipv6.conf.default.ra_honor_pio_life: 0
  • Added: net.ipv6.conf.default.ra_honor_pio_pflag: 0
  • Added: net.ipv6.conf.default.regen_min_advance: 2
  • Added: net.ipv6.conf.docker0.ra_honor_pio_life: 0
  • Added: net.ipv6.conf.docker0.ra_honor_pio_pflag: 0
  • Added: net.ipv6.conf.docker0.regen_min_advance: 2
  • Added: net.ipv6.conf.eth0.ra_honor_pio_life: 0
  • Added: net.ipv6.conf.eth0.ra_honor_pio_pflag: 0
  • Added: net.ipv6.conf.eth0.regen_min_advance: 2
  • Added: net.ipv6.conf.lo.ra_honor_pio_life: 0
  • Added: net.ipv6.conf.lo.ra_honor_pio_pflag: 0
  • Added: net.ipv6.conf.lo.regen_min_advance: 2
  • Added: vm.enable_soft_offline: 1
  • Changed: fs.epoll.max_user_watches: 1809007 -> 1808517
  • Changed: fs.fanotify.max_user_marks: 67544 -> 68412
  • Changed: fs.file-max: 811774 -> 811484
  • Changed: fs.inotify.max_user_watches: 63425 -> 64189
  • Changed: kernel.threads-max: 63487 -> 63178
  • Changed: net.ipv4.tcp_mem: 94041 125391 188082 -> 94017 125357 188034
  • Changed: net.ipv4.udp_mem: 188085 250783 376170 -> 188034 250715 376068
  • Changed: user.max_cgroup_namespaces: 31743 -> 31589
  • Changed: user.max_fanotify_marks: 67544 -> 68412
  • Changed: user.max_inotify_watches: 63425 -> 64189
  • Changed: user.max_ipc_namespaces: 31743 -> 31589
  • Changed: user.max_mnt_namespaces: 31743 -> 31589
  • Changed: user.max_net_namespaces: 31743 -> 31589
  • Changed: user.max_pid_namespaces: 31743 -> 31589
  • Changed: user.max_time_namespaces: 31743 -> 31589
  • Changed: user.max_user_namespaces: 31743 -> 31589
  • Changed: user.max_uts_namespaces: 31743 -> 31589
  • Changed: vm.lowmem_reserve_ratio: 256 256 32 0 0 -> 256 256 32 0
  • Deleted: kernel.sched_child_runs_first: 0

Security

Fixed CVE-2025-0395 in sys-libs/glibc.

Feature

Enabled the Btrfs kernel module.

Fixed

Upgraded chromeos-base/google-breakpad to v2025.07.23.214511-r244.

Fixed

Upgraded chromeos-base/session_manager-client to v0.0.1-r2830.

Fixed

Fixed docker MTU mismatch.

Security

Fixed CVE-20250-3198 in sys-libs/bintuils-libs.

Fixed

Upgraded virtual/logger to v0-r2.

Security

Upgraded elfutils to v0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.

Change

Upgraded nvidia-container-toolkit to v1.17.8. This fixes CVE-2025-23266.

Change

Added support for 7th generation TPU devices.

Fixed

Upgraded net-misc/openssh to 10.0_p1.

Change

iptables-restore.service to start after ipset.service.

Fixed

Upgraded net-misc/socat to v1.8.0.3.

Fixed

Reverted a containerd change which reduced the default soft file descriptor limit for processes in containers to 1024.

Fixed

Added support for the Lustre 2.14.0_p212 drivers.

Security

Fixed CVE-2025-47273 in dev-python/setuptools.

Security

Fixed CVE-2024-23337 in app-misc/jq.

Security

Updated app-editors/nano to v8.5. This resolves CVE-2024-5742.

Security

Updated dev-go/oauth2 to v0.27.0. Fixes CVE-2025-22868.

Fixed

Modified toolbox to use unified cgroup hierarchy mode instead of hybrid mode when possible.

Fixed

Upgraded app-benchmarks/microbenchmarks to v0.0.1-r20.

Fixed

Upgraded app-containers/docker-credential-helpers to v0.9.3.

Fixed

Upgraded sys-apps/pv to v1.9.34.

Fixed

Upgraded sys-process/procps to v4.0.5-r2.

Security

Added support for Nvidia driver version 535.261.03. This fixes CVE-2025-23286 and CVE-2025-23279.

Fixed

Upgraded net-misc/rsync to v3.4.1.

Fixed

Upgraded sys-apps/ethtool to version 6.11.

Security

Fixed CVE-2025-32728 in net-misc/openssh.

Security

Fixed CVE-2024-6174 and CVE-2024-11584 in cloud-init.

Fixed

Upgraded net-nds/rpcbind to v1.2.7.

Security

Fixed CVE-2025-46836 in sys-apps/net-tools

Feature

Updated cos-gpu-installer to v2.4.8: Add the -skip-nvidia-smi flag to disable the execution of nvidia-smi verification during gpu driver installation.

Security

Upgraded net-misc/wget to v1.25.0. This fixes CVE-2024-10524.

Fixed

Upgraded chromeos-base/shill-client to v0.0.1-r4879.

Change

Updated the NVIDIA GPU driver policy for New Feature Branch (NFB) drivers. The LATEST tag has been updated to point to the stable 570.133.20 Production Branch. The 575.57.08 NFB driver remains available for development and testing but must now be selected by its specific version number.Removed 575.57.08 NFB driver support for NVIDIA_GB200 machine.

Feature

Added NVIDIA 570.133.20 vGPU driver.

Change

Upgrade dpdk-kmods to 9b182be2ee4b.

Fixed

Upgraded sys-apps/dbus to v1.16.2-r197.

Fixed

Upgraded app-admin/fluent-bit to v3.2.5.

Fixed

Upgraded sys-apps/diffutils to v3.11-r2.

Security

Upgraded dev-vcs/git to version 2.49.1. This fixes CVE-2025-48385, CVE-2025-27613, CVE-2025-27614, CVE-2025-48384, CVE-2025-46835.

Fixed

Upgraded sys-auth/pambase to v20250228.

Security

Updated dev-go/net in policy manager to v0.39.0. This fixes CVE-2025-22870.

Fixed

Upgraded app-admin/google-guest-configs to v20250718.00.

Fixed

Upgraded app-admin/google-guest-agent to v20250418.00.

Fixed

Upgraded sys-apps/grep to v3.12.

Fixed

Upgraded app-arch/unzip to v6.0_p29.

Fixed

Upgraded dev-libs/double-conversion to v3.3.1.

Change

Fixed an issue that resulted in missing grub boot measurements in some machine configurations.

Fixed

Fixed EINTR error in app-container/cni-plugins.

Security

Fixed CVE-2024-9287 in dev-lang/python.

Fixed

Updated dev-python/botocore to v1.37.9.

Change

Patched a null ptr exception bug in NVIDIA 570.124.06 OSS driver.

Feature

Fixed an issue in containerd that prevented some v2 shims from shutting down properly.

Security

Upgraded dev-go/crypto to v0.35.0. This fixes CVE-2025-22869.

Fixed

Upgraded sys-apps/less to v679.

Fixed

Upgraded chromeos-base/debugd-client to v0.0.1-r2734.

Fixed

Upgraded sys-apps/makedumpfile to v1.7.7.

Security

Upgraded net-misc/curl to v8.12.1. This fixes CVE-2025-0167.

Feature

Added ARM support for the Lustre v2.14.0 drivers.

Security

Upgrade libarchive to v3.8.1. This fixes CVE-2025-5914.

Security

Upgraded vim, vim-core to version 9.1.1500. This fixes CVE-2025-26603, CVE-2025-27423, CVE-2025-29768, CVE-2025-1215, CVE-2025-24014, CVE-2025-22134.

Fixed

Upgraded sys-process/lsof to v4.99.5.

Security

Fixed CVE-2024-13176 in dev-libs/openssl.

Fixed

Updated dev-python/requests to v2.32.4.

Fixed

Increased kdump memory reservation.

Fixed

Upgraded dev-libs/openssl to 3.5.1.

Fixed

Updated dev-python/s3transfer to v0.11.4.

Fixed

Upgraded chromeos-base/minijail to v18-r168.

Security

Fixed CVE-2024-26130 in dev-python/cryptography.

Fixed

Upgraded app-containers/runc to v1.2.5, Upgraded app-containers/runc-test to v1.2.5.

Fixed

Upgraded sys-apps/rootdev to v0.0.1-r51.

Fixed

Fixed issue where modinfo could not display module signatures.

Fixed

Upgraded sys-libs/libseccomp to v2.6.0-r2.

Change

Upgraded the Linux kernel to version 6.12.

Security

Upgraded net-misc/netplan to v1.1.2. This fixes CVE-2022-4968.

Security

Upgraded sys-libs/binutils-libs to version 2.45. This fixes CVE-2025-8224,CVE-2025-8225 and CVE-2025-1153.

Change

Updated Python to v3.11.

Fixed

Updated app-misc/jq to v1.8.1.

Fixed

Upgraded chromeos-base/chromeos-common-script to v0.0.1-r667.

Feature

Added support for NVIDIA GB200 GPU with 570.124.06 GPU driver. This driver version has been assigned the latest, default, and R570 tags for this GPU type.

Fixed

Upgraded app-admin/node-problem-detector to v0.8.20.

Security

Upgraded dev-libs/libxml2 to v1.12.10. Fixes CVE-2025-27113.

Security

Fixed CVE-2025-0840 in binutils.

Security

Fixed CVE-2025-8058 in glibc.

Change

Upgrade cloud-init to v24.4.1.

Fixed

Upgraded sys-libs/libcap to v2.76.

Fixed

Disabled martian logging for ConnectX-7 network cards. These cards only communicate locally, but martian logging during communications with the host can lead to a race condition which causes GID table construction to sometimes fail.

Fixed

Upgraded sys-apps/which to v2.23.

Fixed

Upgraded sys-apps/acl to v2.3.2-r2.

Fixed

Upgraded net-dns/libidn2 to v2.3.8.

Security

Upgraded dev-libs/glib to 2.82.5. This resolves CVE-2024-52533.

Feature

Supported NVIDIA MFT Tools on COS.

Feature

Added support for Nvidia driver version 575.57.08. Added support for NVIDIA_RTX_PRO_6000 devices.

Security

Update NVIDIA GPU drivers to v535.247.01 for default/ R535 and v570.133.20 for latest/R570. This resolves CVE-2025-23244.

Feature

Add support for iRDMA devices.

Fixed

Upgraded app-arch/gzip to v1.14.

Security

Fixed CVE-2024-53427 in app-misc/jq.