Container-Optimized OS Release Notes: Milestone 133

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

August 04, 2026

Change

cos-beta-133-19999-0-7

Kernel Docker Containerd GPU Drivers
COS-6.18.39 v29.4.3 v2.3.2 See List
Breaking

/dev/hugepages is now mounted with the noexec option.

Change

Added a splash screen which is displayed at login.

Change

Added support for net-fs/lustre-client-drivers v2.14.0_p256.

Change

Added support for the Lustre 2.14.0_p246 drivers.

Change

Added support for the Lustre 2.14.0_p249 drivers.

Change

Added support for the R595 Nvidia driver production branch.

Change

Added support for the swiotlb=any kernel command line parameter.

Change

Allow overriding IMA policy from oem partition.

Change

Apply hardening sysctls on cchost boards.

Change

Dropped support for the NVIDIA 535 drivers.

Change

Enabled mm hardening kernel cmdlines on cchost.

Change

Fixed the "CrackArmor" vulnerability in the Linux kernel.

Change

Fixes a kernel panic in virtio_pci teardown when virtually queues are conditionally skipped.

Change

Increased the size of the EFI partition from 32 MiB to 64 MiB and increased the sizes of both kernel partitions from 16 MiB to 32 MiB on x86.

Change

Made it so that /etc/machine-id is mounted with noexec, nosuid, and nodev.

Change

Made it so that /run is mounted as noexec.

Change

On cchost boards, autoload IMA policy on boot.

Change

Set static UUID for the stateful partition.

Change

Switch cchost-* boards to legacy iptables.

Change

Update sys-process/audit to v3.0.9.

Security

Updated app-arch/gzip to v1.14_p20260502, app-arch/xz-utils to v5.4.7, app-arch/zstd to v1.5.7, app-crypt/mit-krb5 to v1.22.2, app-editors/vim to v9.1.2148, app-editors/vim-core to v9.1.2148, dev-libs/libaio to v0.3.113-r2, dev-libs/xxhash to v0.8.3, dev-python/PySocks to v1.6.8, dev-python/markupsafe to v2.1.5, dev-python/pyrsistent to v0.14.11, dev-python/python-magic to v0.4.27, dev-python/pyyaml to v6.0.3, dev-python/rfc3339-validator to v0.1.4-r1, net-misc/rsync to v3.4.4, sys-apps/mawk to v1.3.4_p20260302, sys-libs/libxcrypt to v4.4.38, sys-libs/talloc to v2.4.4, sys-fs/lvm2 to v2.03.39, sys-libs/binutils-libs to v2.46.1.. This resolves CVE-2025-69644.

Change

Updated app-containers/cloud-provider-gcp to v35.0.8, app-containers/docker-credential-gcr to v2.1.32, app-containers/nvidia-container-toolkit to v1.17.9, dev-python/oauthlib to v3.0.2, net-fs/nfs-utils to v2.6.4, sys-libs/libapparmor to v3.1.7..

Change

Updated dev-libs/libtraceevent to v1.7.3, dev-libs/libtracefs to v1.6.4, net-firewall/conntrack-tools to v1.4.9, sys-fs/fuse to v2.9.9, sys-fs/fuse-common to v3.10.5.

Change

Updated google-guest-configs to v20260121.00.

Change

Updated sys-apps/casfs to v0.1.14.

Change

Updated sys-libs/pam to v1.5.3.

Change

Updated the Linux kernel to v6.18.39.

Change

Updated uhaul to v6.18-0.

Change

Upgraded sys-apps/ek-cpu-balloon to v1.2.3.

Change

Upgraded sys-apps/iproute2 to version 6.18.0.

Change

Upgraded sys-apps/xemu to v0.0.9.

Change

Upgraded sys-fs/cryptsetup to v2.8.6.

Change

Upgraded sysram to v6.18-0.

Change

cchost: Add bpf-lsm-policy for VM restrictions.

Change

cchost: Increased the size of the kernel partitions from 16 MiB to 32 MiB.

Feature

Added TPUDirect support.

Feature

Added nvidia-fs support to the COS GPU installer.

Feature

Added support for 590.44.01 and 590.48.01 NVIDIA driver for NVIDIA_RTX_PRO_6000

Feature

Added support for 8th generation TPU devices.

Feature

Added support for NVIDIA driver v535.288.01, v570.211.01 and v580.126.09.

Feature

Added support for larger ring sizes for the GVNIC driver in DQO-QPL mode.

Feature

Added support for loading the ublk kernel module.

Feature

Added support for zswap in the Linux kernel.

Feature

Added the cos_kernel_args tool that allows manipulating kernel command line arguments of a COS image.

Feature

Changed default sysctl networking values on A4x-max machine type only.

Feature

Enabled CONFIG_MEMORY_FAILURE in the Linux kernel for ARM64. This should improve memory errors handling when running CUDA workloads.

Feature

Enabled dynamic configuration of FUSE max pages limit.

Feature

Enabled dynamic debug in the Linux kernel.

Feature

Reverted iproute2 to v5.16.0.

Feature

Switched to using systemd-resolved stub resolver by default, which fixes DNS caching issues.

Fixed

Added support for NVIDIA GRID driver version 580.159.03.

Fixed

Added support for NVIDIA driver v580.126.09-grid for NVIDIA_RTX_PRO_6000 GPU type.

Fixed

Added support for NVIDIA driver v580.159.03.

Fixed

Added support for NVIDIA driver v580.159.04.

Fixed

Added support for NVIDIA driver v595.71.05.

Fixed

Added support for NVIDIA drivers v580.126.16 and v580.126.20.

Fixed

Changed google-guest-agent's plugin installation path to /var/lib/google/guest-agent.

Fixed

Dropped support for NVIDIA MFT Tools v4.32.0.

Fixed

Enabled buffer overflow detection for kernel str/mem functions.

Fixed

Fixed a crash that occurs when using the configfile or source GRUB2 commands when Secure Boot is enabled.

Fixed

Fixed a kernel bug which could cause traffic drops after NIC resets.

Fixed

Fixed an ek-cpu-balloon bug which would result in CPUs being underreported on ek machines with SMT enabled.

Fixed

Update udev rule for protected_stateful_partition

Security

Updated containerd to v2.3.2., containerd-test to v2.3.2.. This resolves CVE-2026-35469, CVE-2026-46680, CVE-2026-50195, CVE-2026-53488, CVE-2026-53492.

Fixed

Updated dev-cpp/abseil-cpp to v20230802.0; dev-libs/flatbuffersto v24.3.25; sys-devel/autofdo to v0.30-r12; media-libs/cros-camera-hal-fake to v0.0.1-r616; chromeos-base/chromeos-dbus-bindings to v0.0.1-r2800; chromeos-base/chromeos-installer to v0.1.0-r4432; chromeos-base/hardware_verifier_proto to v0.0.1-r819; chromeos-base/imageloader to v0.0.1-r2064; chromeos-base/libbrillo to v0.0.1-r2547; chromeos-base/libchrome to v0.0.1-r1242; chromeos-base/libhwsec-foundation to v0.0.1-r826; chromeos-base/libstorage to v0.0.1-r162; chromeos-base/metrics to v0.0.2-r3890; chromeos-base/perfetto to v48.1-r69; chromeos-base/quipper to v0.0.1-r3050; chromeos-base/system_api to v0.0.1-r5972; chromeos-base/update_engine to v0.0.3-r5184; chromeos-base/vboot_reference to v1.0-r2986;dev-rust/vboot_reference-sys to v1.0.0-r36; chromeos-base/verity to v0.0.1-r583; chromeos-base/vpd to v0.0.1-r339; Removed packages dev-util/bazel,dev-util/iwyu, and dev-util/cvise; Removed chromeos-base/crash-reporter.

Fixed

Updated dev-lang/rust, dev-lang/rust-host, dev-lang/rust-bootstrap to v1.84.1; dev-rust/protobuf-codegen to v2.28.0; dev-rust/system_api to v0.24.53-r1596; dev-rust/third-party-crates-src to v0.0.1-r288.

Fixed

Updated dev-libs/isa-l to v2.32.1.

Fixed

Updated sys-devel/gdb to v15.1; sys-apps/flashrom to v0.9.9-r1758; dev-python/cryptography to v43.0.3; Update dev-python/pyopenssl to v24.2.1.

Fixed

Updated sys-devel/llvm to v20.0_pre547379; sys-libs/compiler-rt to v20.0_pre547379; sys-libs/libcxx to v20.0_pre547379; sys-libs/llvm-libunwind to v20.0_pre547379.

Fixed

Upgrade Kubernetes to 1.36.1

Fixed

Upgraded CASFS to v0.1.3.

Fixed

Upgraded app-admin/google-guest-agent to v20260121.00.

Fixed

Upgraded app-admin/google-osconfig-agent to v20260119.00.

Fixed

Upgraded app-admin/logrotate to v3.22.0-r1.

Fixed

Upgraded app-admin/oslogin to v20260626.00.

Fixed

Upgraded app-admin/sosreport to v4.11.2.

Fixed

Upgraded app-arch/unzip to v6.0_p29-r2.

Fixed

Upgraded app-containers/cni-plugins to v1.9.1.

Fixed

Upgraded app-containers/docker to v29.4.3, Upgraded app-containers/docker-test to v29.4.3, Upgraded app-containers/docker-cli to v29.4.3.

Fixed

Upgraded app-containers/docker-credential-helpers to v0.9.8.

Fixed

Upgraded app-crypt/sbsigntools to v0.42.0, and net-misc/m2crypto to v0.42.0.

Fixed

Upgraded app-emulation/cloud-init to v26.1.

Fixed

Upgraded app-shells/dash to v0.5.13.4-r2.

Fixed

Upgraded chromeos-base/chromeos-common-script to v0.0.1-r672.

Fixed

Upgraded chromeos-base/debugd-client to v0.0.1-r2739.

Fixed

Upgraded chromeos-base/google-breakpad to v2026.06.22.165940-r278.

Fixed

Upgraded chromeos-base/power_manager-client to v0.0.1-r2973.

Fixed

Upgraded chromeos-base/session_manager-client to v0.0.1-r2834.

Fixed

Upgraded cos-gpu-installer to v2.7.4.

Fixed

Upgraded dev-db/sqlite to v3.53.3.

Fixed

Upgraded dev-libs/expat to v2.8.2.

Fixed

Upgraded dev-libs/openssl from v3.5.6 to v4.0.0.

Fixed

Upgraded dev-util/gn to v2331.

Fixed

Upgraded dev-utils/gdbus-codegen to v2.86.3.

Fixed

Upgraded net-firewall/iptables to v1.8.13.

Fixed

Upgraded net-libs/libnetfilter_conntrack to v1.1.1.

Fixed

Upgraded net-libs/libnetfilter_queue to v1.0.5-r1.

Fixed

Upgraded net-misc/chrony to v4.8-r2.

Security

Upgraded net-misc/curl to 8.21.0. to fix CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, CVE-2025-15224, CVE-2026-1965, CVE-2026-3783, CVE-2026-4873, CVE-2026-5545, CVE-2026-5773, CVE-2026-6253, CVE-2026-6276, CVE-2026-6429, CVE-2026-7009, CVE-2026-7168.

Fixed

Upgraded net-misc/socat to v1.8.1.3.

Fixed

Upgraded sys-apps/acl to v2.4.0.

Fixed

Upgraded sys-apps/attr to v2.6.0.

Fixed

Upgraded sys-apps/file to v5.47-r1.

Fixed

Upgraded sys-apps/gentoo-functions to v1.7.7.

Fixed

Upgraded sys-apps/hwdata to v0.401.

Fixed

Upgraded sys-apps/less to v704.

Fixed

Upgraded sys-apps/makedumpfile to v1.7.9.

Fixed

Upgraded sys-apps/pv to v1.10.4.

Fixed

Upgraded sys-libs/libcap to v2.78.

Fixed

Upgraded sys-libs/libcap-ng to v0.9.3.

Fixed

Upgraded sys-libs/zlib to v1.3.2-r1.

Fixed

Upgraded sys-process/lsof to v4.99.6.

Fixed

Upgraded sys-process/procps to v4.0.6.

Fixed

Upgraded the dump capture kernel to Linux v6.18.

Fixed

Upgraded the galog version to v0.0.0-20250924170816-9dbf105986f4 in google-guest-agent to fix an issue with high CPU consumption.

Fixed

Upgraded virtual/logger to v0-r3.

Security

Fixed CVE-2025-15281 and CVE-2026-0861 in sys-libs/glibc.

Security

Fixed CVE-2025-40147 in the Linux kernel.

Security

Fixed CVE-2026-0915 in sys-apps/glibc.

Security

Fixed CVE-2026-0994 in dev-libs/protobuf.

Security

Fixed CVE-2026-27135 in net-libs/nghttp2.

Security

Fixed CVE-2026-29111 in sys-apps/systemd

Security

Fixed CVE-2026-32597 with pyjwt package upgrade to v2.12.1.

Security

Fixed CVE-2026-33997 and CVE-2026-34040 in Docker.

Security

Fixed CVE-2026-34743 in app-arch/xz-utils.

Security

Fixed CVE-2026-35385 and CVE-2026-35386 in net-misc/openssh.

Security

Fixed CVE-2026-35414 in net-misc/openssh.

Security

Fixed CVE-2026-40225 in sys-apps/systemd.

Security

Fixed CVE-2026-40226 in sys-apps/systemd.

Security

Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.

Security

Fixed CVE-2026-4046 in sys-libs/glibc.

Security

Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.

Security

Fixed CVE-2026-44431 in dev-python/urllib3.

Security

Fixed CVE-2026-50195, CVE-2026-53488, CVE-2026-53492, CVE-2026-53489, and CVE-2026-47262 in app-containers/containerd.

Security

Fixed CVE-2026-58469, CVE-2026-58471, CVE-2026-58472 in net-misc/wget.

Security

Fixed CVE-2026-5928 in sys-libs/glibc.

Security

Fixed CVE-2026-6238 in sys-libs/glibc.

Security

Fixed CVE-2026-6732 in dev-libs/libxml2.

Security

Fixed CVE-2026-7210 in dev-lang/python.

Security

Fixed EFI variable OOB read in grub config parsing.

Security

Fixed KCTF-329f0b9 in the Linux kernel.

Security

Fixed KCTF-7cb9a23 in the Linux kernel.

Security

Fixed KCTF-c9bc175 in the Linux kernel.

Security

Fixed KCTF-e3f000f in the Linux kernel.

Security

Fixed KCTF-f8db647 in the Linux kernel.

Security

Fixed argument injection in toolbox.

Security

Updated dev-lang/go to 1.25.10. This fixes CVE-2026-33814,CVE-2026-39819,CVE-2026-39823,CVE-2026-39825,CVE-2026-42499,CVE-2026-39817,CVE-2026-39820,CVE-2026-39826,CVE-2026-39836.

Security

Updated dev-libs/libxml2 to version 2.14.6. This resolves CVE-2025-6021.

Security

Updated dev-python/pyjwt to v2.13.0. This fixes CVE-2026-48522, CVE-2026-48524, CVE-2026-48525, CVE-2026-485256.

Security

Updated glib to v2.89.1., gdbus-codegen to v2.89.1.. This resolves CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, CVE-2026-58016.

Security

Updated go to v1.25.9. This resolves CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, CVE-2026-27140, CVE-2026-27144.

Security

Upgraded dev-libs/glib to v2.86.3. This fixes CVE-2025-14087, CVE-2025-14512 and CVE-2025-13601.

Security

Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.

Security

Upgraded dev-libs/openssl to v3.5.7 to fix CVE-2025-15467, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31790, CVE-2026-34180, CVE-2026-34181, CVE-2026-34182, CVE-2026-34183, CVE-2026-42764, CVE-2026-45445, CVE-2026-45447, CVE-2026-7383, CVE-2026-9076.

Security

Upgraded net-misc/openssh to 10.3_p1. to fix CVE-2026-35387, CVE-2026-35388.

Change

Runtime sysctl changes:

  • Changed: net.ipv4.udp_mem: 188034 250715 376068 -> 188034 250714 376068