This document lists the changes for the patch versions of the Google Kubernetes Engine (GKE) 1.32 minor version.
These changelogs are supplementary information about the updates to specific GKE system components. For information about features, changes, and security issues in GKE, see the following documents:
- Product updates: GKE release notes
- Security vulnerabilities: Security bulletins
1.32.13-gke.2504000
The following sections describe changes in this patch version when compared with the previous patch version, 1.32.13-gke.2427000. For information about upstream Kubernetes changes, see the Kubernetes v1.32.13 changelog.
Kubernetes Updates
k8s-api
Updated k8s-api cohort from version 1.32.13-gke.700 to 1.32.13-gke.900.
- Miscellaneous:
- Updated the Go runtime to version 1.27.1 and updated base images (including go-runner and setcap) for core Kubernetes components.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
filestorecsi
Updated filestorecsi component from version 0.15.48 to 0.15.49.
- Security Fixes:
- Updated
google.golang.org/grpcandgolang.org/x/cryptoto resolve CVE-2026-84304 and CVE-2026-56854.
- Updated
- Miscellaneous:
- Updated the Go toolchain and container base images for Filestore CSI driver components.
gcsfusecsi
Updated gcsfusecsi component from version 0.9.77 to 0.9.78.
- Security Fixes:
- Updated the google.golang.org/grpc module to v1.83.1 and the CSI node driver registrar image to resolve CVE-2026-84304.
gvisor
Updated gvisor component from version 1.32.3 to 1.32.6.
- Miscellaneous:
- Updated the container base image to
gke_distroless_20260915.00_p0.
- Updated the container base image to
osimage
Updated osimage component from version 1.32.174 to 1.32.176.
- Features:
- Updated the Linux kernel to version 6.6.153.
- Updated Docker to v27.5.1.
- Updated Containerd to v2.0.10.
- Bug Fixes:
- Fixed an issue with
docker cpwhere copying to or from containers with symlinked bind mounts would fail.
- Fixed an issue with
- Security Fixes:
- Fixed a vulnerability in sys-libs/glibc: CVE-2026-6238.
- Updated dev-go/net to v0.55.0 to resolve CVE-2026-25680.
- Miscellaneous:
- Updated system packages: google-guest-configs to v20260819.00, docker-credential-helpers to v0.9.9, sqlite to v3.53.4, libnftnl to v1.2.9, and passwdqc to v2.0.3-r1.
pdcsi
Updated pdcsi component from version 0.21.97 to 0.21.100.
- Security Fixes:
- Updated
csi-provisionerto address vulnerabilities: CVE-2026-29181, CVE-2026-39883, CVE-2026-41178, CVE-2026-56854, GO-2026-6061, and GO-2026-6094. - Updated
csi-attacherto address vulnerability: GO-2026-6061. - Updated
csi-resizerto address vulnerabilities: CVE-2026-41178, GO-2026-5841, and GO-2026-6061. - Updated snapshot sidecar images (
snapshot-controller,csi-snapshotter, andcsi-snapshot-validation-webhook) to address vulnerabilities: CVE-2026-41178 and GO-2026-6061. - Updated dependencies to resolve security vulnerabilities: CVE-2025-65637, CVE-2026-41178, CVE-2026-46600, CVE-2026-56852, CVE-2026-56865, CVE-2026-78662, CVE-2026-84304, and GO-2026-6061.
- Updated golang.org/x/crypto in csi-provisioner to resolve CVE-2026-78662.
- Updated google.golang.org/grpc in csi-node-driver-registrar to resolve CVE-2026-84304 and CVE-2026-84445.
- Updated
- Miscellaneous:
- Updated the Go runtime to versions 1.25.14 and 1.27.1 across CSI sidecar images.
- Updated base images for
csi-provisioner,csi-attacher,csi-resizer,csi-node-driver-registrar, and snapshot components to the latest distroless versions.
workloadautoscaler
Updated workloadautoscaler component from version 15.14.0 to 15.16.0.
- Miscellaneous:
- Updated Vertical Pod Autoscaler (VPA) components, including the admission controller, recommender, and updater, to version 0.23.0-gke.20.
1.32.13-gke.2427000
The following sections describe changes in this patch version when compared with the previous patch version, 1.32.13-gke.2411000. For information about upstream Kubernetes changes, see the Kubernetes v1.32.13 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
gcsfusecsi
Updated gcsfusecsi component from version 0.9.76 to 0.9.77.
- Miscellaneous:
- Updated the Go runtime and base images for the gcs-fuse-csi-driver, csi-node-driver-registrar, gcs-fuse-csi-driver-sidecar-mounter, and gcs-fuse-csi-driver-metadata-prefetch components.
kube-addon-manager
Updated kube-addon-manager component from version 31.0.21 to 31.0.22.
- Miscellaneous:
- Updated the
gke-distroless/bashcontainer image to versiongke_distroless_20260815.00_p0.
- Updated the
1.32.13-gke.2411000
There are no customer-facing updates in this version when compared to the previous patch version, 1.32.13-gke.2393000. For information about upstream Kubernetes changes, see the Kubernetes v1.32.13 changelog.
1.32.13-gke.2393000
The following sections describe changes in this patch version when compared with the previous patch version, 1.32.13-gke.2337000. For information about upstream Kubernetes changes, see the Kubernetes v1.32.13 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
gcsfusecsi
Updated gcsfusecsi component from version 0.9.74 to 0.9.76.
- Security Fixes:
- Fixed the following container CVEs: CVE-2025-22871, CVE-2026-27143, CVE-2026-33186, CVE-2026-39821, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39834, CVE-2026-42508, and CVE-2026-46595.
- Miscellaneous:
- Updated Golang base images to version 1.25.14 for the CSI driver, sidecar mounter, metadata prefetch, and webhook.
osimage
Updated osimage component from version 1.32.166 to 1.32.174.
- Features:
- Added support for net-fs/lustre-client-drivers v2.14.0_p259.
- Updated Linux kernel to COS-6.6.153.
- Updated Docker to v27.5.1.
- Updated Containerd to v2.0.10.
- Updated cos-gpu-installer to v2.7.7.
- Bug Fixes:
- Updated dev-lang/go to version 1.25.12.
- Upgraded system packages and utilities to improve stability: app-admin/google-guest-configs (v20260804.00), app-arch/zstd (v1.5.7-r1), app-shells/dash (v0.5.13.5), dev-libs/expat (v2.8.3), dev-libs/libverto (v0.3.2-r1), dev-libs/popt (v1.19-r1), dev-libs/xxhash (v0.8.3-r2), sys-apps/acl (v2.4.0-r2), sys-apps/xemu (v0.0.10), and sys-process/lsof (v4.99.7).
- Security Fixes:
- Fixed CVE-2026-64279 in the Linux kernel.
- Fixed CVE-2026-64319 in the Linux kernel.
- Fixed CVE-2026-64352 in the Linux kernel.
- Fixed CVE-2026-64375 in the Linux kernel.
- Fixed CVE-2026-64401 in the Linux kernel.
- Fixed CVE-2026-64413 in the Linux kernel.
- Fixed CVE-2026-64474 in the Linux kernel.
- Fixed CVE-2026-64476 in the Linux kernel.
- Fixed CVE-2026-64535 in the Linux kernel.
- Fixed KCTF-8173f7e in the Linux kernel.
- Fixed CVE-2026-64561 in the Linux kernel.
- Fixed CVE-2026-64562 in the Linux kernel.
- Fixed CVE-2026-64572 in the Linux kernel.
- Fixed CVE-2026-64576 in the Linux kernel.
- Fixed CVE-2026-64579 in the Linux kernel.
- Fixed CVE-2026-64580 in the Linux kernel.
- Fixed CVE-2026-64597 in the Linux kernel.
- Fixed CVE-2026-64598 in the Linux kernel.
- Fixed CVE-2026-64604 in the Linux kernel.
- Fixed CVE-2026-68093 in the Linux kernel.
- Fixed CVE-2026-68116 in the Linux kernel.
- Fixed CVE-2026-68147 in the Linux kernel.
- Fixed CVE-2026-68184 in the Linux kernel.
- Fixed CVE-2026-68186 in the Linux kernel.
- Fixed CVE-2026-68187 in the Linux kernel.
- Fixed CVE-2026-68284 in the Linux kernel.
- Fixed CVE-2026-68325 in the Linux kernel.
- Fixed CVE-2026-68336 in the Linux kernel.
- Fixed CVE-2026-68338 in the Linux kernel.
- Fixed CVE-2026-68343 in the Linux kernel.
- Fixed CVE-2026-68386 in the Linux kernel.
- Fixed CVE-2026-68398 in the Linux kernel.
- Fixed CVE-2026-68425 in the Linux kernel.
- Fixed CVE-2026-68428 in the Linux kernel.
- Fixed CVE-2026-68096 in the Linux kernel.
- Fixed CVE-2026-68129 in the Linux kernel.
- Fixed CVE-2026-68146 in the Linux kernel.
- Fixed CVE-2026-68149 in the Linux kernel.
- Fixed CVE-2026-68171 in the Linux kernel.
- Fixed CVE-2026-68299 in the Linux kernel.
- Fixed CVE-2026-68329 in the Linux kernel.
- Fixed KCTF-0650f1c in the Linux kernel.
- Fixed vulnerabilities in the Linux kernel: CVE-2026-64371, CVE-2026-68142, and CVE-2026-68432.
- Updated dev-libs/libxml2 to v2.15.3 to resolve CVE-2026-0989, CVE-2026-0990, and CVE-2026-0992.
- Miscellaneous:
- Updated system image base to version cos-121-18867-528-58.
1.32.13-gke.2337000
The following sections describe changes in this patch version when compared with the previous patch version, 1.32.13-gke.2314000. For information about upstream Kubernetes changes, see the Kubernetes v1.32.13 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
advanceddatapath
Updated advanceddatapath component from version 32.3.76 to 32.3.77.
- Security Fixes:
- Fixed security vulnerability GO-2026-4440 in
golang.org/x/net. - Fixed security vulnerability GO-2026-5942 in
golang.org/x/net. - Fixed security vulnerability GO-2026-5970 in
golang.org/x/text.
- Fixed security vulnerability GO-2026-4440 in
- Miscellaneous:
- Updated Cilium components, including the agent, operator, and Hubble relay/CLI, to version v1.16.8-gke1.32-gke.107.
customer-logs-exporter
Updated customer-logs-exporter component from version 1.32.1-gke.25 to 1.32.1-gke.26.
- Miscellaneous:
- Updated the
gke-distroless/bashbase image to a newer version.
- Updated the
gcsfusecsi
Updated gcsfusecsi component from version 0.9.73 to 0.9.74.
- Security Fixes:
- Updated Go modules and dependencies to address identified security vulnerabilities.
gpu-device-plugin
Updated gpu-device-plugin component from version 1.32.6-gke.19 to 1.32.7-gke.0.
- Miscellaneous:
- Updated Go builder versions to 1.24 for the NRI injector and persistenced installer.