This document lists the changes for the patch versions of the Google Kubernetes Engine (GKE) 1.31 minor version.
These changelogs are supplementary information about the updates to specific GKE system components. For information about features, changes, and security issues in GKE, see the following documents:
- Product updates: GKE release notes
- Security vulnerabilities: Security bulletins
1.31.14-gke.2630000
The following sections describe changes in this patch version when compared with the previous patch version, 1.31.14-gke.2613000. For information about upstream Kubernetes changes, see the Kubernetes v1.31.14 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
advanceddatapath
Updated advanceddatapath component from version 31.6.80 to 31.6.81.
- Security Fixes:
- Updated
golang.org/x/netto resolve security vulnerability GO-2026-4440. - Updated
golang.org/x/netto resolve security vulnerability GO-2026-5942. - Updated
golang.org/x/textto resolve security vulnerability GO-2026-5970.
- Updated
customer-logs-exporter
Updated customer-logs-exporter component from version 1.31.4-gke.34 to 1.31.4-gke.35.
- Security Fixes:
- Updated the
gke-distroless/bashbase image to include the latest security fixes and package updates.
- Updated the
gcsfusecsi
Updated gcsfusecsi component from version 0.8.97 to 0.8.98.
- Miscellaneous:
- Updated the Go runtime and container base images for the CSI driver.
- Updated the
csi-node-driver-registrarsidecar image to versionv2.10.1-gke.91.
gpu-device-plugin
Updated gpu-device-plugin component from version 1.31.1-gke.17 to 1.31.2-gke.0.
- Security Fixes:
- Updated Go module dependencies to address known security vulnerabilities.
osimage
Updated osimage component from version 1.31.177 to 1.31.179.
- Features:
- Updated Linux kernel to COS-6.6.143.
- Updated Docker to v24.0.9.
- Updated Containerd to v1.7.34.
- Bug Fixes:
- Added support for net-fs/lustre-client-drivers v2.14.0_p259.
- Upgraded sys-apps/xemu to v0.0.10.
- Updated dev-lang/go to version 1.25.12.
- Upgraded net-fs/cifs-utils to v7.7.
- Upgraded sys-libs/talloc to v2.4.4-r1.
- Resolved a bug in the XFS file system where direct I/O writes could utilize outdated block mappings during Copy-on-Write (CoW) operations.
- Upgraded net-misc/curl to version 8.21.0.
- Security Fixes:
- CVE-2026-68096: Fixed in the Linux kernel.
- CVE-2026-68116: Fixed in the Linux kernel.
- CVE-2026-68129: Fixed in the Linux kernel.
- CVE-2026-68146: Fixed in the Linux kernel.
- CVE-2026-68147: Fixed in the Linux kernel.
- CVE-2026-68149: Fixed in the Linux kernel.
- CVE-2026-68171: Fixed in the Linux kernel.
- CVE-2026-68325: Fixed in the Linux kernel.
- CVE-2026-68386: Fixed in the Linux kernel.
- CVE-2026-68428: Fixed in the Linux kernel.
- KCTF-0650f1c: Fixed vulnerability in the Linux kernel.
- Fixed CVE-2026-64227 in the Linux kernel.
- Fixed CVE-2026-64476 in the Linux kernel.
- Fixed CVE-2026-64561 in the Linux kernel.
- Fixed CVE-2026-64562 in the Linux kernel.
- Fixed CVE-2026-64572 in the Linux kernel.
- Fixed CVE-2026-64576 in the Linux kernel.
- Fixed CVE-2026-64579 in the Linux kernel.
- Fixed CVE-2026-64580 in the Linux kernel.
- Fixed CVE-2026-64597 in the Linux kernel.
- Fixed CVE-2026-64598 in the Linux kernel.
- Fixed CVE-2026-64604 in the Linux kernel.
- Fixed CVE-2026-68093 in the Linux kernel.
- Fixed CVE-2026-68184 in the Linux kernel.
- Fixed CVE-2026-68186 in the Linux kernel.
- Fixed CVE-2026-68187 in the Linux kernel.
- Fixed CVE-2026-68284 in the Linux kernel.
- Fixed CVE-2026-68299 in the Linux kernel.
- Fixed CVE-2026-68329 in the Linux kernel.
- Fixed CVE-2026-68336 in the Linux kernel.
- Fixed CVE-2026-68338 in the Linux kernel.
- Fixed CVE-2026-68343 in the Linux kernel.
- Fixed CVE-2026-68388 in the Linux kernel.
- Fixed CVE-2026-68398 in the Linux kernel.
- Fixed CVE-2026-68425 in the Linux kernel.
- Fixed CVE-2026-64279 in the Linux kernel.
- Fixed CVE-2026-64319 in the Linux kernel.
- Fixed CVE-2026-64352 in the Linux kernel.
- Fixed CVE-2026-64375 in the Linux kernel.
- Fixed CVE-2026-64401 in the Linux kernel.
- Fixed CVE-2026-64413 in the Linux kernel.
- Fixed CVE-2026-64535 in the Linux kernel.
- Fixed CVE-2026-64548 in the Linux kernel.
- Fixed CVE-2026-64556 in the Linux kernel.
- Fixed KCTF-8173f7e in the Linux kernel.
- Fixed CVE-2026-35177 in app-editors/vim and app-editors/vim-core.
- Fixed multiple vulnerabilities in dev-go/crypto: CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, and CVE-2026-46598.
- Fixed CVE-2026-58470 in net-misc/wget.
- Fixed CVE-2026-59890 in dev-python/setuptools.
- Fixed CVE-2026-58055 in net-libs/nghttp2.
- Fixed multiple vulnerabilities in the Linux kernel: CVE-2026-64244, CVE-2026-64247, CVE-2026-64266, CVE-2026-64294, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64313, CVE-2026-64317, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64326, CVE-2026-64355, CVE-2026-64368, CVE-2026-64370, CVE-2026-64373, CVE-2026-64379, CVE-2026-64380, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64411, CVE-2026-64412, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64456, CVE-2026-64474, CVE-2026-64475, CVE-2026-64507, CVE-2026-64508, CVE-2026-64512, CVE-2026-64514, CVE-2026-64530, CVE-2026-64534, CVE-2026-64538, CVE-2026-64545, CVE-2026-64546, CVE-2026-64552, and CVE-2026-64554.
- Fixed CVE-2026-29111 in sys-apps/systemd.
- Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.
- Fixed CVE-2026-6019 in dev-lang/python.
- Fixed multiple security vulnerabilities in the Linux kernel: CVE-2026-53381, CVE-2026-53385, CVE-2026-53388, CVE-2026-53391, CVE-2026-53397, CVE-2026-53398, CVE-2026-63794, CVE-2026-63795, CVE-2026-63800, CVE-2026-63802, CVE-2026-63807, CVE-2026-63809, CVE-2026-63823, CVE-2026-63824, CVE-2026-63827, CVE-2026-63828, and CVE-2026-63830.
- Updated containerd to v1.7.34 to resolve CVE-2026-46680 and CVE-2026-53488.
- Fixed CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, and CVE-2026-58016 in glib.
- Fixed CVE-2025-13462, CVE-2026-3644, and CVE-2026-4224 in dev-lang/python.
- Fixed CVE-2026-43010, CVE-2026-46135, CVE-2026-46331, CVE-2026-53163, and CVE-2026-53167 in the Linux kernel.
- Fixed CVE-2026-58469, CVE-2026-58471, and CVE-2026-58472 in net-misc/wget.
- Fixed CVE-2026-40225 in sys-apps/systemd.
- Fixed CVE-2026-53362 in the Linux kernel.
- Fixed KCTF-7cb9a23 in the Linux kernel.
- Miscellaneous:
- Synchronized image components with COS-117-18613-675-64.
- Upgraded net-libs/nghttp2 to 1.69.0.
- Updated base image to cos-arm64-117-18613-675-11.