Send feedback
Security bulletins
Stay organized with collections
Save and categorize content based on your preferences.
This document describes security bulletins for Distributed Cloud
(software only) for VMware and bare metal. The bulletins in this document start
from June 1, 2026. To view bulletins for these products for dates prior to June
1, 2026, see GKE security
bulletins .
GCP-2026-051
Published: 2026-07-31
Reference:
CVE-2026-50195 ,
CVE-2026-53488 ,
CVE-2026-53492 ,
CVE-2026-53489 ,
CVE-2026-47262
VMware
Description
Severity
The following vulnerabilities have been discovered in containerd (the GDC container
runtime). These vulnerabilities allow attackers with permissions to create Pods to
bypass Kubernetes security boundaries and perform host compromise, cache poisoning,
and denial of service. While these vulnerabilities are critical in the context of
containerd, the requirement to have cluster privileges to create Pods to exploit them
means they are considered High according to GDC (software only) vulnerability
classification.
CVE-2026-50195 (Critical) : containerd's CRI checkpoint import process fails to
validate image references. An attacker with permissions to create Pods can use a
crafted checkpoint image to poison the node's local image cache, causing other pods
to use a malicious image.
CVE-2026-53488 (Critical) : CRI plugin propagates labels from an image config to a
container without validation. This may result in executing an arbitrary command on
the host.
CVE-2026-53492 (Critical) : CRI implementation improperly trusts Container Device
Interface (CDI) annotations during container restoration. This allows an attacker to
inject arbitrary CDI configurations (such as host mounts and device nodes) into
restored containers, bypassing resource allocation and device plugin enforcement.
CVE-2026-53489 (High) : CRI plugin restores container.log without validating a
symlinked path, allowing an attacker to read arbitrary host files via kubectl logs.
CVE-2026-47262 (Moderate) : A vulnerability in containerd allows a maliciously
crafted image to cause memory exhaustion (DoS) of the containerd process.
These vulnerabilities affect all GDC (software only) configurations using
Container-Optimized OS and Ubuntu node images.
What should I do?
For GDC software only on VMware, the following patches will contain fixes for the
vulnerabilities:
High
Bare metal
Description
Severity
The following vulnerabilities have been discovered in containerd (the GDC container
runtime). These vulnerabilities allow attackers with permissions to create Pods to
bypass Kubernetes security boundaries and perform host compromise, cache poisoning,
and denial of service. While these vulnerabilities are critical in the context of
containerd, the requirement to have cluster privileges to create Pods to exploit them
means they are considered High according to GDC (software only) vulnerability
classification.
CVE-2026-50195 (Critical) : containerd's CRI checkpoint import process fails to
validate image references. An attacker with permissions to create Pods can use a
crafted checkpoint image to poison the node's local image cache, causing other pods
to use a malicious image.
CVE-2026-53488 (Critical) : CRI plugin propagates labels from an image config to a
container without validation. This may result in executing an arbitrary command on
the host.
CVE-2026-53492 (Critical) : CRI implementation improperly trusts Container Device
Interface (CDI) annotations during container restoration. This allows an attacker to
inject arbitrary CDI configurations (such as host mounts and device nodes) into
restored containers, bypassing resource allocation and device plugin enforcement.
CVE-2026-53489 (High) : CRI plugin restores container.log without validating a
symlinked path, allowing an attacker to read arbitrary host files via kubectl logs.
CVE-2026-47262 (Moderate) : A vulnerability in containerd allows a maliciously
crafted image to cause memory exhaustion (DoS) of the containerd process.
These vulnerabilities affect all GDC (software only) configurations using Ubuntu node
images.
What should I do?
For GDC software only on bare metal, the following patches will contain fixes for the
vulnerabilities issue:
High
Send feedback
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License , and code samples are licensed under the Apache 2.0 License . For details, see the Google Developers Site Policies . Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2026-07-31 UTC.
Need to tell us more?
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-07-31 UTC."],[],[]]