<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:cos-dev-release-notes</id>
  <title>Container Optimized OS dev - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/cos-dev-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2025-11-03T00:00:00-08:00</updated>

  <entry>
    <title>November 03, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#November_03_2025</id>
    <updated>2025-11-03T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#November_03_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19350-0-0_">cos-dev-129-19350-0-0 <a id='"cos-arm64-dev-129-19350-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/38ea339c697dd371bf1ca35bb23ca1bf49b19a82
">COS-6.12.55</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19350.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811495 -&gt; 811384</li>
</ul></p>
<h3>Feature</h3>
<p>Fixed a bug in cos-extensions which would cause GB200 and GB300 devices not to be detected in one code path, which would result in Imex channels not being created by default.</p>
<h3>Fixed</h3>
<p>Fixed a TCPX bug which would sometimes incorrectly report devices as being missing when route cache entries were missing or invalidated.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.55.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 27, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#October_27_2025</id>
    <updated>2025-10-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#October_27_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19340-0-0_">cos-dev-129-19340-0-0 <a id='"cos-arm64-dev-129-19340-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/cfe88d85f71d7502f55ff3e7ceebcb6c65f8b5bb
">COS-6.12.54</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19340.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Added GB300 support to cos-extensions.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v535.274.02 and v570.195.03.</p>
<h3>Change</h3>
<p>Updated cos-gpu-installer to v2.5.9. This adds support for installing drivers for GB 300 devices.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v685.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/pv to v1.9.44.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.54.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-11413 and CVE-2025-11414 in binutils-libs.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2025.10.16.221019-r255.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 24, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#October_24_2025</id>
    <updated>2025-10-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#October_24_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19334-0-0_">cos-dev-129-19334-0-0 <a id='"cos-arm64-dev-129-19334-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/873f2db84b5c40b7a0efab7db35eff2471f51e16
">COS-6.12.53</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19334.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2025-11495 in binutils-libs.</p>
<h3>Change</h3>
<p>Updated app-containers/runc to v1.2.7.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-11494 in binutils-libs.</p>
<h3>Fixed</h3>
<p>Upgraded sys-auth/pambase to v20251013.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20251014.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/pv to v1.9.42.</p>
<h3>Change</h3>
<p>Updated cos-gpu-installer to v2.5.8.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-11412 in binutils-libs.</p>
<h3>Feature</h3>
<p>Added support for NVIDIA GB300 devices.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.400.</p>
<h3>Change</h3>
<p>Added support for A4X-Max NICs.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 20, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#October_20_2025</id>
    <updated>2025-10-20T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#October_20_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19326-0-0_">cos-dev-129-19326-0-0 <a id='"cos-arm64-dev-129-19326-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/873f2db84b5c40b7a0efab7db35eff2471f51e16
">COS-6.12.53</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19326.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811438 -&gt; 811426</li>
</ul></p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.53.</p>
<h3>Fixed</h3>
<p>Updated the dump capture kernel to v6.12.52.</p>
<h3>Security</h3>
<p>Fixed KCTF-6bb73db in the Linux Kernel.</p>
<h3>Fixed</h3>
<p>Reduced gcr_wait_online retry gap.</p>
<h3>Fixed</h3>
<p>Updated golang.org/x/crypto, golang.org/x/net, and
golang.org/x/oauth2 in kubelet and kubectl.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 13, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#October_13_2025</id>
    <updated>2025-10-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#October_13_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19319-0-0_">cos-dev-129-19319-0-0 <a id='"cos-arm64-dev-129-19319-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3c1532a68eb1ef3c5e11dc5b860713612086c4ce
">COS-6.12.50</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19319.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811493 -&gt; 811438</li>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.399.</p>
<h3>Feature</h3>
<p>Added support for NVIDIA driver v580.95.05. Updated all latest driver version and default driver versions for NVIDIA_GB200 and NVIDIA_B200 to v580.95.05.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.50.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.4.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libtirpc to v1.3.7.</p>
<h3>Security</h3>
<p>Updated sys-apps/coreutils to v9.5. This resolves
CVE-2024-0684.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-11081, CVE-2025-11082 and CVE-2025-11083 in sys-libs/binutils-libs.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.7.3.</p>
<h3>Fixed</h3>
<p>Updated toolbox container image tag to v20251002.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2025.10.06.205107-r254.</p>
<h3>Security</h3>
<p>Updated dev-python/urllib3 to v2.5.0. This resolves
CVE-2025-50181.</p>
<h3>Security</h3>
<p>Fixed KCTF-134121b in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded open-vm-tools to 13.0.5. This fixes CVE-2025-41244 in anthos variant.</p>
<h3>Fixed</h3>
<p>Partially fixed an issue where excessive contention among writeback kworkers when switching a large number of inodes between cgroups could lead to system unresponsiveness.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>October 06, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#October_06_2025</id>
    <updated>2025-10-06T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#October_06_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19302-0-0_">cos-dev-129-19302-0-0 <a id='"cos-arm64-dev-129-19302-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/bca084acf36df7105bde6e24bdee99b4cc82df6b
">COS-6.12.49</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19302.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Add support for NVIDIA MFT Tools v4.33.0.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811490 -&gt; 811493</li>
<li>Changed: net.ipv4.udp_mem: 188034   250715  376068 -&gt; 188034    250714  376068</li>
</ul></p>
<h3>Feature</h3>
<p>Configured the cos-gpu-installer to use R580 drivers as the
default GPU drivers.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.49.</p>
<h3>Security</h3>
<p>Updated dev-python/jinja to v3.1.6. This resolves
CVE-2024-56326, CVE-2024-56201 and CVE-2025-27516.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 29, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#September_29_2025</id>
    <updated>2025-09-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#September_29_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19290-0-0_">cos-dev-129-19290-0-0 <a id='"cos-arm64-dev-129-19290-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/062ea04d39b48ae7b92268575cd91677e97dd59d
">COS-6.12.48</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19290.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Updated golang.org/x/oauth2, golang.org/x/net, golang.org/x/crypto, and github.com/golang-jwt/jwt/v5 in Docker.</p>
<h3>Feature</h3>
<p>Added CPU balloon support for ARM CPUs.</p>
<h3>Feature</h3>
<p>Added support for the fwctl subsystem and the Mellanox fwctl driver for ARM64.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.7.2.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.48.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250913.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-auth/pambase to v20250906.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 24, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#September_24_2025</id>
    <updated>2025-09-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#September_24_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19284-0-0_">cos-dev-129-19284-0-0 <a id='"cos-arm64-dev-129-19284-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/cae186e568245769d61ab1cff0f14366822276c7
">COS-6.12.47</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19284.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.82.07.
Updated all latest driver version and default driver
versions for NVIDIA_GB200 and NVIDIA_B200 to v580.82.07.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.47.</p>
<h3>Change</h3>
<p>Enabled Coherent Driver Memory Management by default when installing GPU drivers on GB2000.</p>
<h3>Change</h3>
<p>Updated cos-gpu-installer to v2.5.7.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/libxslt to version 1.1.43-r1.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811423 -&gt; 811483</li>
<li>Changed: net.ipv4.udp_mem: 188034   250715  376068 -&gt; 188034    250714  376068</li>
</ul></p>
<h3>Security</h3>
<p>Upgraded dev-libs/libxml2 to version 2.13.9. This fixes
CVE-2025-9714, CVE-2025-32415 and CVE-2025-32414.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 16, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#September_16_2025</id>
    <updated>2025-09-16T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#September_16_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19279-0-0_">cos-dev-129-19279-0-0 <a id='"cos-arm64-dev-129-19279-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/345ad6a408b0f8b808d2818aafac95e470de47c1
">COS-6.12.46</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19279.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Fixed a kernel bug which caused boot to fail for n4 machine types.</p>
<h3>Feature</h3>
<p>Added GDRCopy kernel module for NVIDIA drivers.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.46.</p>
<h3>Feature</h3>
<p>Added support for NVIDIA MFT Tools on arm64.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811510 -&gt; 811423</li>
</ul></p>
]]>
    </content>
  </entry>

  <entry>
    <title>September 08, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#September_08_2025</id>
    <updated>2025-09-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#September_08_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19271-0-0_">cos-dev-129-19271-0-0 <a id='"cos-arm64-dev-129-19271-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e342d60a146658d84ddceee66940ed6686f19d93
">COS-6.12.43</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19271.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Enabled dynamic vlan configuration for non-primary NICs.</p>
<h3>Change</h3>
<p>Added kernel support for bare-metal on the NVIDIA Grace platform.</p>
<h3>Fixed</h3>
<p>Fixed an issue where cpusets cgroups did not work with
cgroup v1 enabled.</p>
<h3>Feature</h3>
<p>Added iRDMA support in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-auth/pambase to v20250826.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.46-r3.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-6052 in dev-libs/glib.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.43.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.398.</p>
<h3>Feature</h3>
<p>Disabled DNSSEC by default for COS TPU VMs.</p>
<h3>Fixed</h3>
<p>Installed app-misc/c_rehash.</p>
<h3>Feature</h3>
<p>Added TDX RTMR support.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811419 -&gt; 811510</li>
</ul></p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2025.08.18.161925-r245.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250818.00.</p>
<h3>Feature</h3>
<p>Added IPv6 support for machines using the IDPF driver.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250826.00.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 25, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#August_25_2025</id>
    <updated>2025-08-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#August_25_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19251-0-0_">cos-dev-129-19251-0-0 <a id='"cos-arm64-dev-129-19251-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/bb106cd2966ddeca447529bc878f7ec95ed4e9c2
">COS-6.12.42</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19251.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Added support for the Lustre 2.14.0_p216 drivers.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811494 -&gt; 811419</li>
</ul></p>
<h3>Security</h3>
<p>Fixed KCTF-abad3d0 in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 18, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#August_18_2025</id>
    <updated>2025-08-18T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#August_18_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19246-0-0_">cos-dev-129-19246-0-0 <a id='"cos-arm64-dev-129-19246-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ef55a40bd2b3af2acd1197d83f203f892d717819
">COS-6.12.41</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19246.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Upgraded sys-libs/binutils-libs to version 2.45. This fixes CVE-2025-8224,CVE-2025-8225 and CVE-2025-1153.</p>
<h3>Fixed</h3>
<p>Upgraded net-nds/rpcbind to v1.2.8.</p>
<h3>Feature</h3>
<p>Enabled the google-guest-agent's network management functionality.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/gentoo-functions to v1.7.4.</p>
<h3>Fixed</h3>
<p>Upgraded dev-lang/go to v1.23.12.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r668.</p>
<h3>Security</h3>
<p>Fixed KCTF-01d3c84 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250807.00.</p>
<h3>Feature</h3>
<p>Added ConnectX-8 RDMA support.</p>
<h3>Feature</h3>
<p>Backported support for AMD SEV-SNP SVSM vTPM driver and
configfs-tsm addition for extended attestation protocol.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.50.4.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>August 12, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#August_12_2025</id>
    <updated>2025-08-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#August_12_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-129-19226-0-0_">cos-dev-129-19226-0-0 <a id='"cos-arm64-dev-129-19226-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/0c333f6a7b49b4a001ab23fca27c39d4f694ebcd
">COS-6.12.41</a></td>
<td>v27.5.1</td>
<td>v2.1.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19226.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Upgraded urllib3 to version 1.26.18. This fixes CVE-2021-33503, CVE-2023-43804, and CVE-2023-45803.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-8058 in glibc.</p>
<h3>Security</h3>
<p>Added support for Nvidia driver version 535.261.03. This fixes CVE-2025-23286 and CVE-2025-23279.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811510 -&gt; 811531</li>
</ul></p>
<h3>Fixed</h3>
<p>Removed an artifact registry ping that would delay multi-user.target indefinitely for machines with no external IP address.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/openssl to 3.5.1.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2025.07.23.214511-r244.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/openssh to 10.0_p1.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sudo to v1.9.17_p2.</p>
<h3>Fixed</h3>
<p>Updated dev-python/requests to v2.32.4.</p>
<h3>Security</h3>
<p>Upgraded net-misc/netplan to 1.1.2. This fixes
CVE-2022-4968.</p>
<h3>Fixed</h3>
<p>Updated app-admin/node-problem-detector to 0.8.21.</p>
<h3>Security</h3>
<p>Added support for Nvidia driver version 570.172.08. This fixes CVE-2025-23279.</p>
<h3>Fixed</h3>
<p>Upgraded dev-lang/go to v1.23.11.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250718.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/pv to v1.9.34.</p>
<h3>Fixed</h3>
<p>Fixed an issue where the cpuidle driver selected for some
machine types would cause inflated reports of high CPU usage.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.50.3.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/glib to 2.82.5. This resolves
CVE-2024-52533.</p>
<h3>Change</h3>
<p>Updated containerd to v2.1.3.</p>
<h3>Fixed</h3>
<p>Updated app-containers/cni-plugins to 1.7.1.</p>
<h3>Security</h3>
<p>Upgraded dev-vcs/git to version 2.49.1. This fixes CVE-2025-48385, CVE-2025-27613, CVE-2025-27614, CVE-2025-48384, CVE-2025-46835.</p>
<h3>Fixed</h3>
<p>Upgraded virtual/logger to v0-r2.</p>
<h3>Feature</h3>
<p>Enabled hardware optimized SHA256 algorithms for x86 machines with SSSE3 and AVX/AVX2 instructions and ARM64 machines with SHA-NI and ARMv8 Crypto Extensions.</p>
<h3>Feature</h3>
<p>Enabled the Btrfs kernel module.</p>
<h3>Fixed</h3>
<p>Reverted a containerd change which reduced the default soft file descriptor limit for processes in containers to 1024.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/minijail to v18-r168.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.5.</p>
<h3>Feature</h3>
<p>Removed the cloud-final.service dependency on multi-user.target which could delay cloud-init user-data scripts indefinitely when long-running startup scripts are used.</p>
<h3>Feature</h3>
<p>Added NVIDIA GPU driver's R580 branch. Updated the LATEST GPU driver label to version 580.65.06.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4879.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 30, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#July_30_2025</id>
    <updated>2025-07-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#July_30_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-19175-0-0_">cos-dev-125-19175-0-0 <a id='"cos-arm64-dev-125-19175-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/dfb6569157e957816a33d329705284d2ef5a390e
">COS-6.12.37</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19175.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Upgraded sqlite to v3.50.2. This resolves CVE-2025-6965.</p>
<h3>Fixed</h3>
<p>The NFS access cache is no longer cleared on login by default. To use the old behavior, load the NFS module with the <code>nfs_fasc=1</code> module parameter.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811539 -&gt; 811510</li>
</ul></p>
<h3>Fixed</h3>
<p>Updated app-misc/jq to v1.8.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-26130 in dev-python/cryptography.</p>
<h3>Security</h3>
<p>Patched openssl to fix CVE-2023-50782 affecting
dev-python/crytography.</p>
<h3>Security</h3>
<p>Fixed KCTF-5e28d5a in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>July 24, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#July_24_2025</id>
    <updated>2025-07-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#July_24_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-19165-0-0_">cos-dev-125-19165-0-0 <a id='"cos-arm64-dev-125-19165-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/0ce36d1d9a8a3cab6816b03d67f80f64e582deb7
">COS-6.12.37</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19165.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded uhaul to version 6.12-0.</p>
<h3>Change</h3>
<p>Updated the NVIDIA GPU driver policy for New Feature Branch (NFB) drivers. The LATEST tag has been updated to point to the stable 570.133.20 Production Branch. The 575.57.08 NFB driver remains available for development and testing but must now be selected by its specific version number.Removed 575.57.08 NFB driver support for NVIDIA_GB200 machine.</p>
<h3>Security</h3>
<p>Updated app-editors/nano to v8.5. This resolves
CVE-2024-5742.</p>
<h3>Security</h3>
<p>Upgraded vim, vim-core to
version 9.1.1500. This fixes CVE-2025-26603, CVE-2025-27423,
CVE-2025-29768, CVE-2025-1215, CVE-2025-24014, CVE-2025-22134.</p>
<h3>Feature</h3>
<p>Remove support for the v2.14.0_p184 and v2.14.0_p198 Lustre client drivers.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250627.00.</p>
<h3>Feature</h3>
<p>Added ARM support for the Lustre 2.14.0 drivers.</p>
<h3>Fixed</h3>
<p>Fixed an issue where some workloads could cause a full
system hang when running close to their memory limit.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.37.</p>
<h3>Change</h3>
<p>Upgraded nvidia-container-toolkit to v1.17.8. This fixes CVE-2025-23266.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4875.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-6174 and CVE-2024-11584 in cloud-init.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2025.07.01.161305-r243.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Added: kernel.apparmor_restrict_unprivileged_unconfined: 0</li>
<li>Added: kernel.core_file_note_size_limit: 4194304</li>
<li>Added: kernel.core_sort_vma: 0</li>
<li>Added: net.ipv4.fib_multipath_hash_seed: 0</li>
<li>Added: net.ipv4.tcp_pingpong_thresh: 1</li>
<li>Added: net.ipv6.conf.all.ra_honor_pio_life: 0</li>
<li>Added: net.ipv6.conf.all.ra_honor_pio_pflag: 0</li>
<li>Added: net.ipv6.conf.all.regen_min_advance: 2</li>
<li>Added: net.ipv6.conf.default.ra_honor_pio_life: 0</li>
<li>Added: net.ipv6.conf.default.ra_honor_pio_pflag: 0</li>
<li>Added: net.ipv6.conf.default.regen_min_advance: 2</li>
<li>Added: net.ipv6.conf.docker0.ra_honor_pio_life: 0</li>
<li>Added: net.ipv6.conf.docker0.ra_honor_pio_pflag: 0</li>
<li>Added: net.ipv6.conf.docker0.regen_min_advance: 2</li>
<li>Added: net.ipv6.conf.eth0.ra_honor_pio_life: 0</li>
<li>Added: net.ipv6.conf.eth0.ra_honor_pio_pflag: 0</li>
<li>Added: net.ipv6.conf.eth0.regen_min_advance: 2</li>
<li>Added: net.ipv6.conf.lo.ra_honor_pio_life: 0</li>
<li>Added: net.ipv6.conf.lo.ra_honor_pio_pflag: 0</li>
<li>Added: net.ipv6.conf.lo.regen_min_advance: 2</li>
<li>Added: vm.enable_soft_offline: 1</li>
<li>Changed: fs.epoll.max_user_watches: 1809007 -&gt; 1808517</li>
<li>Changed: fs.fanotify.max_user_marks: 67544 -&gt; 68412</li>
<li>Changed: fs.file-max: 811755 -&gt; 811539</li>
<li>Changed: fs.inotify.max_user_watches: 63425 -&gt; 64189</li>
<li>Changed: kernel.threads-max: 63487 -&gt; 63178</li>
<li>Changed: net.ipv4.tcp_mem: 94041    125391  188082 -&gt; 94017 125357  188034</li>
<li>Changed: net.ipv4.udp_mem: 188085   250783  376170 -&gt; 188034    250715  376068</li>
<li>Changed: user.max_cgroup_namespaces: 31743 -&gt; 31589</li>
<li>Changed: user.max_fanotify_marks: 67544 -&gt; 68412</li>
<li>Changed: user.max_inotify_watches: 63425 -&gt; 64189</li>
<li>Changed: user.max_ipc_namespaces: 31743 -&gt; 31589</li>
<li>Changed: user.max_mnt_namespaces: 31743 -&gt; 31589</li>
<li>Changed: user.max_net_namespaces: 31743 -&gt; 31589</li>
<li>Changed: user.max_pid_namespaces: 31743 -&gt; 31589</li>
<li>Changed: user.max_time_namespaces: 31743 -&gt; 31589</li>
<li>Changed: user.max_user_namespaces: 31743 -&gt; 31589</li>
<li>Changed: user.max_uts_namespaces: 31743 -&gt; 31589</li>
<li>Changed: vm.lowmem_reserve_ratio: 256   256 32  0   0 -&gt; 256    256 32  0</li>
<li>Deleted: kernel.sched_child_runs_first: 0</li>
</ul></p>
<h3>Change</h3>
<p>Updated cos-gpu-installer to v2.5.5.</p>
<h3>Fixed</h3>
<p>Upgraded sysram to version 6.12-0.</p>
<h3>Security</h3>
<p>Upgraded app-admin/sudo to v1.9.17_p1. This resolves
CVE-2025-32462 and CVE-2025-32463.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 30, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#June_30_2025</id>
    <updated>2025-06-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#June_30_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-19126-0-0_">cos-dev-125-19126-0-0 <a id='"cos-arm64-dev-125-19126-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ffa537805d6bb853cb6baacb2d70fb7fadba42e0
">COS-6.6.94</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19126.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2025.06.12.121629-r242.</p>
<h3>Security</h3>
<p>Upgrade libarchive to version 3.8.1. This fixes CVE-2025-5914.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r667.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4871.</p>
<h3>Change</h3>
<p>Updated nvidia-container-toolkit to v1.17.7.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v679.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4872.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.50.1.</p>
<h3>Change</h3>
<p>Upgraded sys-apps/ethtool to version 6.11.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/procps to v4.0.5-r2.</p>
<h3>Fixed</h3>
<p>Upgraded dev-lang/go to v1.23.10.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811773 -&gt; 811755</li>
</ul></p>
<h3>Fixed</h3>
<p>Added support for the Lustre 2.14.0_p212 drivers.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250605.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libcap to v2.76.</p>
<h3>Fixed</h3>
<p>drop marvell-pcie-ep-octeon driver</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sudo to v1.9.17.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 23, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#June_23_2025</id>
    <updated>2025-06-23T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#June_23_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-125-19115-0-0_">cos-125-19115-0-0 <a id='"cos-arm64-125-19115-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ffa537805d6bb853cb6baacb2d70fb7fadba42e0
">COS-6.6.94</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19115.0.0/csql-arm64-gcp/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Added NVIDIA 570.133.20 vGPU driver.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.6.94.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811736 -&gt; 811773</li>
</ul></p>
<h3>Security</h3>
<p>Upgraded elfutils to version 0.193. This fixes CVE-2025-1365, CVE-2025-1371, CVE-2025-1372, and CVE-2025-1377.</p>
<h3>Feature</h3>
<p>Added a kernel patch to address bcache latency.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 18, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#June_18_2025</id>
    <updated>2025-06-18T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#June_18_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-19104-0-0_">cos-dev-125-19104-0-0 <a id='"cos-arm64-dev-125-19104-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8f1ed7554eff45bf08c26fd7f15bc57a7ffac0b0
">COS-6.6.93</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19104.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Upgraded app-misc/jq to v1.8.0. This fixes CVE-2025-48060.</p>
<h3>Change</h3>
<p>Upgraded dpdk-kmods to 9b182be2ee4b</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811779 -&gt; 811736</li>
</ul></p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.6.93.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 17, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#June_17_2025</id>
    <updated>2025-06-17T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#June_17_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-19094-0-0_">cos-dev-125-19094-0-0 <a id='"cos-arm64-dev-125-19094-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8ff56aa9d000fc42d1198f5e46504f60c75f29b2
">COS-6.6.92</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19094.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated cos-gpu-installer to v2.5.3.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811798 -&gt; 811779</li>
</ul></p>
<h3>Security</h3>
<p>Fixed KCTF-ac9fe7d in the kernel.</p>
<h3>Feature</h3>
<p>Added support for Nvidia driver version 575.57.08.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4869.</p>
<h3>Security</h3>
<p>Updated systemd to v254.26. This resolves CVE-2025-4598.</p>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p198 drivers.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.50.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-47273 in dev-python/setuptools.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 02, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#June_02_2025</id>
    <updated>2025-06-02T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#June_02_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-19071-0-0_">cos-dev-125-19071-0-0 <a id='"cos-arm64-dev-125-19071-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/1c5a7e09f4791a79a02ae7d83967cd3e13b12755
">COS-6.6.92</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19071.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed KCTF-3f98113 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250516.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v678.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/rootdev to v0.0.1-r51.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/dbus to v1.16.2-r197.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/power_manager-client to v0.0.1-r2969.</p>
<h3>Fixed</h3>
<p>Upgraded dev-lang/go to v1.23.9.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2025.05.22.184901-r240.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.6.92.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811729 -&gt; 811798</li>
<li>Changed: net.ipv6.conf.docker0.mtu: 1500 -&gt; 1460</li>
</ul></p>
<h3>Security</h3>
<p>Fixed CVE-2025-46836 in sys-apps/net-tools</p>
<h3>Feature</h3>
<p>Injected IMEX channel char device for GB200 GPUs.</p>
<h3>Fixed</h3>
<p>Updated cos-gpu-installer to v2.5.2: Added support for OTHER/NO_GPU cases to enable GPU driver preloading on the ARM64 architecture and added support for IMEX Driver configuration installation for NVIDIA_GB200 machine.</p>
<h3>Security</h3>
<p>Upgraded net-misc/curl to version 8.12.1. This fixes CVE-2025-0167.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-23337 in app-misc/jq.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/debugd-client to v0.0.1-r2734.</p>
<h3>Fixed</h3>
<p>Fixed docker MTU mismatch.</p>
<h3>Feature</h3>
<p>Supported NVIDIA MFT Tools.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r665.</p>
<h3>Security</h3>
<p>Fixed CVE-20250-3198 in sys-libs/bintuils-libs.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4866.</p>
<h3>Change</h3>
<p>Upgraded google-guest-agent to 20250327.00. This included
new services like <code>google-guest-compat-manager.service</code> and
<code>google-guest-agent-manager.service</code> and new binaries like
<code>google_guest_compat_manager</code>, <code>gce_metadata_script_runner</code>,
<code>google_guest_agent_manager</code>, <code>ggactl_plugin_cleanup</code> and
<code>gce_compat_metadata_script_runner</code>.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/session_manager-client to v0.0.1-r2830.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.49.2.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 12, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#May_12_2025</id>
    <updated>2025-05-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_12_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-19041-0-0_">cos-dev-125-19041-0-0 <a id='"cos-arm64-dev-125-19041-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/886b1d9ff3fa338cc9fcf17a29044e75e53b7703
">COS-6.6.89</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19041.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.6.89.</p>
<h3>Fixed</h3>
<p>Fixed issue where modinfo could not display module signatures.</p>
<h3>Change</h3>
<p>Added support for 7th generation TPU devices.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811773 -&gt; 811729</li>
</ul></p>
<h3>Security</h3>
<p>Updated apparmor to 3.1.6. This fixes CVE-2016-1585.</p>
<h3>Change</h3>
<p>Upgraded app-admin/google-guest-configs to v20250501.00.</p>
<h3>Fixed</h3>
<p>Increased kdump memory reservation.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 05, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#May_05_2025</id>
    <updated>2025-05-05T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_05_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-19025-0-0_">cos-dev-125-19025-0-0 <a id='"cos-arm64-dev-125-19025-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/47fa00f1eb2c0c37a5e65a0a1c80fb8a0688bbcb
">COS-6.6.88</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19025.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.7.</p>
<h3>Fixed</h3>
<p>Upgraded app-arch/gzip to v1.14.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4853.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/debugd-client to v0.0.1-r2733.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/minijail to v18-r167.</p>
<h3>Fixed</h3>
<p>Upgraded net-dns/libidn2 to v2.3.8.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/update_engine-client to v0.0.1-r2480.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/session_manager-client to v0.0.1-r2829.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/power_manager-client to v0.0.1-r2968.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r664.</p>
<h3>Security</h3>
<p>Updated NVIDIA GPU drivers to v535.247.01 for default/ R535
and v570.133.20 for latest/R570. This resolves CVE-2025-23244.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2025.04.09.155244-r236.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.6.88.</p>
<h3>Fixed</h3>
<p>Upgraded app-benchmarks/microbenchmarks to v0.0.1-r20.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-32414, CVE-2025-32415 in dev-libs/libxml2.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-agent to v20250418.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/grep to v3.12.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250409.00.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811785 -&gt; 811773</li>
</ul></p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 29, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#April_29_2025</id>
    <updated>2025-04-29T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#April_29_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-19014-0-0_">cos-dev-125-19014-0-0 <a id='"cos-arm64-dev-125-19014-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/9eb015595552064b6c350316a7f0306e41d6d7a5
">COS-6.6.87</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19014.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Fixed an issue in containerd that potentially breaks metric collection</p>
<h3>Security</h3>
<p>Fixed CVE-2025-31498 in net-dns/c-ares.</p>
<h3>Change</h3>
<p>Patched a null ptr exception bug in NVIDIA 570.124.06 OSS driver</p>
<h3>Security</h3>
<p>Fixed CVE-2025-32728 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Updated dev-go/net in policy manager to v0.39.0. This fixes CVE-2025-22870.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811798 -&gt; 811785</li>
</ul></p>
<h3>Feature</h3>
<p>Fixed an issue in containerd that prevented some v2 shims from shutting down properly.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 25, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#April_25_2025</id>
    <updated>2025-04-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#April_25_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-19000-0-0_">cos-dev-125-19000-0-0 <a id='"cos-arm64-dev-125-19000-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/9eb015595552064b6c350316a7f0306e41d6d7a5
">COS-6.6.87</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/19000.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-agent to v20250408.00.</p>
<h3>Change</h3>
<p>Updated cos-gpu-installer to v2.5.0: Support IMEX Driver installation for NVIDIA_GB200 GPU device.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811798 -&gt; 811749</li>
</ul></p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4850.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-48615 in app-arch/libarchive.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-53427 in app-misc/jq.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.6.87.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r663.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/debugd-client to v0.0.1-r2732.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/session_manager-client to v0.0.1-r2828.</p>
<h3>Security</h3>
<p>Updated dev-vcs/git to version 2.49.0. This fixed CVE-2024-52006, CVE-2024-50349</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/power_manager-client to v0.0.1-r2967.</p>
<h3>Fixed</h3>
<p>Reverted a change in the linux kernel which caused nfs directories to unexpectedly be mounted as ro instead of rw.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/update_engine-client to v0.0.1-r2479.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 14, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#April_14_2025</id>
    <updated>2025-04-14T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#April_14_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-18986-0-0_">cos-dev-125-18986-0-0 <a id='"cos-arm64-dev-125-18986-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/2557fdc73daef656ca9f8bc1effa5556585fce67
">COS-6.6.86</a></td>
<td>v27.5.1</td>
<td>v2.0.4</td>
<td><a href="https://storage.googleapis.com/cos-tools/18986.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/power_manager-client to v0.0.1-r2966.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/minijail to v18-r164.</p>
<h3>Fixed</h3>
<p>Fixed EINTR error in app-container/cni-plugins.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2025.04.01.213855-r235.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250328.00.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.7.1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/dbus to v1.14.10-r196.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.6.86.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811816 -&gt; 811798</li>
</ul></p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/session_manager-client to v0.0.1-r2827.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/debugd-client to v0.0.1-r2731.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/update_engine-client to v0.0.1-r2478.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.1.</p>
<h3>Fixed</h3>
<p>Upgraded app-arch/unzip to v6.0_p29.</p>
<h3>Fixed</h3>
<p>Modified toolbox to use unified cgroup hierarchy mode, when possible, instead of hybrid mode.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/diffutils to v3.11-r2.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r662.</p>
<h3>Fixed</h3>
<p>Upgraded net-nds/rpcbind to v1.2.7.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/nss to v3.110.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4848.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.3.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-agent to v20250331.00.</p>
<h3>Change</h3>
<p>Updated app-containers/containerd to v2.0.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0-r2.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 31, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#March_31_2025</id>
    <updated>2025-03-31T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_31_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-18971-0-0_">cos-dev-125-18971-0-0 <a id='"cos-arm64-dev-125-18971-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/9857d2c2b7785dd30c7e318c69665eb2c1697afb
">COS-6.6.84</a></td>
<td>v27.5.1</td>
<td>v2.0.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/18971.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.6.84.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811727 -&gt; 811816</li>
</ul></p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 24, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#March_24_2025</id>
    <updated>2025-03-24T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_24_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-125-18964-0-0_">cos-dev-125-18964-0-0 <a id='"cos-arm64-dev-125-18964-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/7095dbb4f54c2e428d26a28dc463f6494687d53c
">COS-6.6.83</a></td>
<td>v27.5.1</td>
<td>v2.0.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/18964.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated app-admin/google-guest-configs to v20250207.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/dbus to v1.14.10-r195.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-agent to v20250304.03.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/minijail to v18-r163.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/pv to v1.9.27.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/debugd-client to v0.0.1-r2727.</p>
<h3>Security</h3>
<p>Upgraded net-misc/wget to version 1.25.0. Fixes
CVE-2024-10524.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0.</p>
<h3>Feature</h3>
<p>Support for NVIDIA B200 GPU – Added support for the R570 driver series, including version 570.86.15. This version has been assigned the latest, default, and R570 tags.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.0.3.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/session_manager-client to v0.0.1-r2817.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4838.</p>
<h3>Feature</h3>
<p>Applied Intel patches to add iRDMA support in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Updated dev-python/botocore to v1.37.9.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/nss to v3.109.</p>
<h3>Change</h3>
<p>Updated Python to v3.11.</p>
<h3>Fixed</h3>
<p>Upgraded sys-auth/pambase to v20250228.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/fluent-bit to v3.2.5.</p>
<h3>Fixed</h3>
<p>Updated app-admin/awscli to v1.38.4.</p>
<h3>Feature</h3>
<p>Added support for NVIDIA GB200 GPU with 570.124.06 GPU driver. This driver version has been assigned the latest, default, and R570 tags for this GPU type.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-agent to v20250122.00.</p>
<h3>Security</h3>
<p>Updated dev-go/oauth2 to v0.27.0. Fixes CVE-2025-22868.</p>
<h3>Change</h3>
<p>Upgraded app-containers/docker to v27.5.1, Upgraded app-containers/docker-test to v27.5.1, Upgraded app-containers/docker-cli to v27.5.1.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.49.1.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4834.</p>
<h3>Security</h3>
<p>Upgraded dev-go/crypto to v0.35.0. This fixes CVE-2025-22869.</p>
<h3>Feature</h3>
<p>Updated cos-gpu-installer to v2.4.7:
1.Added Support for NVIDIA B200 GPU. 2.Enabled --prepare-build-tools flag to preload GPU driver metadata for ARM64</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libxml2 to version 1.12.10. Fixes CVE-2025-27113.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-agent to v20250204.02.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-0395 in sys-libs/glibc.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811701 -&gt; 811727</li>
</ul></p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/nss to v3.108.</p>
<h3>Fixed</h3>
<p>Disabled martian logging for ConnectX-7 network cards. These cards only communicate locally, but martian logging during communications with the host can lead to a race condition which causes GID table construction to sometimes fail.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2024.02.16.014630-r227.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r659.</p>
<h3>Change</h3>
<p>Upgrade cloud-init from 23.4.3 to 24.4.1.</p>
<h3>Change</h3>
<p>Fixed an issue that resulted in missing grub boot measurements in some machine configurations.</p>
<h3>Fixed</h3>
<p>Fixed a race condition that could cause a kernel panic.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/power_manager-client to v0.0.1-r2963.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/update_engine-client to v0.0.1-r2471.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/update_engine-client to v0.0.1-r2474.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r657.</p>
<h3>Feature</h3>
<p>Added support for the Lustre 2.14.0 client drivers.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250124.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/diffutils to v3.11-r1.</p>
<h3>Security</h3>
<p>Upgrade sys-libs/binutils-libs to 2.44-r1. This fixes CVE-2024-53589.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/dbus to v1.14.10-r194.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/debugd-client to v0.0.1-r2728.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/diffutils to v3.11.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20250221.00.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/minijail to v18-r160.</p>
<h3>Feature</h3>
<p>Add support for iRDMA devices.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/session_manager-client to v0.0.1-r2821.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/pv to v1.9.31.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-agent to v20250225.00.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/power_manager-client to v0.0.1-r2961.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-0840 in binutils.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/runc to v1.2.5, Upgraded app-containers/runc-test to v1.2.5.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/debugd-client to v0.0.1-r2726.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.391.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.2.</p>
<h3>Fixed</h3>
<p>Updated dev-python/python-dateutil to v2.9.0.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/session_manager-client to v0.0.1-r2820.</p>
<h3>Feature</h3>
<p>Added support for NVIDIA 570.124.06 GPU driver.
Updated the LATEST GPU driver label to version 570.124.06 for all GPU devices.
Updated the DEFAULT GPU driver label to version 570.124.06 for NVIDIA_B200 and NVIDIA_H200 GPU devices.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/double-conversion to v3.3.1.</p>
<h3>Security</h3>
<p>Upgraded net-misc/openssh to version 9.9_p2. This fixed CVE-2025-26465 and CVE-2025-26466.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.47.2-r1.</p>
<h3>Feature</h3>
<p>Updated cos-gpu-installer to v2.4.8: Add the -skip-nvidia-smi flag to disable the execution of nvidia-smi verification during gpu driver installation.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/session_manager-client to v0.0.1-r2818.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/which to v2.23.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0-r1.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4818.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-13176 in dev-libs/openssl.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/node-problem-detector to v0.8.20.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-9287 in dev-lang/python.</p>
<h3>Change</h3>
<p>Updated the default tag of the GPU driver supporting the NVIDIA H200 GPU device to 570.86.15.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r658.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/power_manager-client to v0.0.1-r2962.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/shill-client to v0.0.1-r4825.</p>
<h3>Fixed</h3>
<p>Updated dev-python/s3transfer to v0.11.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/acl to v2.3.2-r2.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/update_engine-client to v0.0.1-r2470.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 17, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#March_17_2025</id>
    <updated>2025-03-17T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_17_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-121-18867-0-53_">cos-dev-121-18867-0-53 <a id='"cos-arm64-dev-121-18867-0-53"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6cfb17261b700344d310a61dfc731347f6191083
">COS-6.6.74</a></td>
<td>v27.5.1</td>
<td>v2.0.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.0.53/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.0.3.</p>
<h3>Security</h3>
<p>Upgraded net-misc/openssh to version 9.9_p2. This fixed CVE-2025-26465 and CVE-2025-26466.</p>
<h3>Security</h3>
<p>Upgraded dev-go/oauth2 to v0.27.0. This fixes CVE-2025-22868.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-50014 in the Linux kernel.</p>
<h3>Feature</h3>
<p>Added support for iRDMA devices.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-50017 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded app-containers/docker to v27.5.1, Upgraded app-containers/docker-test to v27.5.1, Upgraded app-containers/docker-cli to v27.5.1.</p>
<h3>Security</h3>
<p>Fixed KCTF-fcdd224 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-21745 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-go/crypto to v0.35.0. This fixes CVE-2025-22869.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-50304 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-21814 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libxml2 to version 1.12.10. This fixes CVE-2025-27113.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-21690 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Disabled martian logging for ConnectX-7 network cards. These cards only communicate locally, but martian logging during communications with the host can lead to a race condition which causes GID table construction to sometimes fail.</p>
<h3>Security</h3>
<p>Fixed KCTF-638ba50 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-49994 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-50146 in the Linux kernel.</p>
<h3>Feature</h3>
<p>Applied Intel patches to add iRDMA support in the Linux kernel.</p>
<h3>Feature</h3>
<p>Updated cos-gpu-installer to v2.4.8: Add the -skip-nvidia-smi flag to disable the execution of nvidia-smi verification during gpu driver installation.</p>
<h3>Security</h3>
<p>Fixed KCTF-8802766 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded net-misc/wget to version 1.25.0. This fixes
CVE-2024-10524.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811788 -&gt; 811701</li>
<li>Deleted: net.bridge.bridge-nf-call-arptables: 1</li>
<li>Deleted: net.bridge.bridge-nf-call-ip6tables: 1</li>
<li>Deleted: net.bridge.bridge-nf-call-iptables: 1</li>
<li>Deleted: net.bridge.bridge-nf-filter-pppoe-tagged: 0</li>
<li>Deleted: net.bridge.bridge-nf-filter-vlan-tagged: 0</li>
<li>Deleted: net.bridge.bridge-nf-pass-vlan-input-dev: 0</li>
</ul></p>
<h3>Security</h3>
<p>Fixed CVE-2024-56549 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgrade sys-libs/binutils-libs to 2.44-r1. This fixes CVE-2024-53589.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-58017 in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>February 24, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#February_24_2025</id>
    <updated>2025-02-24T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#February_24_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-121-18867-0-24_">cos-dev-121-18867-0-24 <a id='"cos-arm64-dev-121-18867-0-24"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/bc67b314e6581abe448ef9194130530bf0872262
">COS-6.6.74</a></td>
<td>v25.0.7</td>
<td>v2.0.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.0.24/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded sys-apps/diffutils to v3.11.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/fluent-bit to v3.2.5.</p>
<h3>Change</h3>
<p>Updated the default tag of the GPU driver supporting the NVIDIA H200 GPU device to 570.86.15.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-9287 in dev-lang/python.</p>
<h3>Change</h3>
<p>Updated app-admin/google-guest-configs to v20250207.00.</p>
<h3>Change</h3>
<p>Updated Konlet to v0.13.4.</p>
<h3>Feature</h3>
<p>Updated cos-gpu-installer to v2.4.7:
1.Added Support for NVIDIA B200 GPU. 2.Enabled --prepare-build-tools flag to preload GPU driver metadata for ARM64</p>
<h3>Change</h3>
<p>Upgraded cloud-init from 23.4.3 to 24.4.1.</p>
<h3>Change</h3>
<p>Fixed CVE-2025-0840 in binutils.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/pv to v1.9.27.</p>
<h3>Feature</h3>
<p>Support for NVIDIA B200 GPU – Added support for the R570 driver series, including version 570.86.15. This version has been assigned the latest, default, and R570 tags.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811771 -&gt; 811788</li>
</ul></p>
<h3>Security</h3>
<p>Fixed CVE-2024-13176 in dev-libs/openssl.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-0395 in sys-libs/glibc.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.391.</p>
<h3>Change</h3>
<p>Upgraded app-admin/google-guest-agent to v20250204.02.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>February 03, 2025</title>
    <id>tag:google.com,2016:cos-dev-release-notes#February_03_2025</id>
    <updated>2025-02-03T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#February_03_2025"/>
    <content type="html"><![CDATA[<h3>Change</h3>
<h3 id="cos-dev-121-18865-0-0_">cos-dev-121-18865-0-0 <a id='"cos-arm64-dev-121-18865-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/989d6b4926a38e7cdfa63d3c941bdbd435e3f90c
">COS-6.6.74</a></td>
<td>v25.0.7</td>
<td>v2.0.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/18865.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed KCTF-bc50835 in the Linux kernel.</p>
<h3>Feature</h3>
<p>Enabled ECC kernel modules required for confidential GPU functionality.</p>
<h3>Feature</h3>
<p>Enabled Grace platform support: Enabled ATS/PASID(PCI) for
ARM64 kernel.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.6.74.</p>
<h3>Feature</h3>
<p>Enabled Grace platform support: Enabled SMMU (v3) for ARM64
kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: fs.file-max: 811821 -&gt; 811771</li>
</ul></p>
<h3>Feature</h3>
<p>Enabled Grace platform support: Enabled memory_hotplug and
device_private in the ARM64 kernel.</p>
<h3>Feature</h3>
<p>Enabled Grace platform support: Enabled DMA-BUF shared
memory support for the ARM64 kernel.</p>
<h3>Feature</h3>
<p>Added NVIDIA GPU driver's R570 branch. Updated the LATEST GPU driver label to version 570.86.15.</p>
<h3>Feature</h3>
<p>Backported Intel TDX (Trust Domain Extensions) and confidential computing patches from Linux kernel 6.7 upstream to enable TDX feature support.</p>
]]>
    </content>
  </entry>

</feed>
