This document lists the changes for the patch versions of the Google Kubernetes Engine (GKE) 1.33 minor version.
These changelogs are supplementary information about the updates to specific GKE system components. For information about features, changes, and security issues in GKE, see the following documents:
- Product updates: GKE release notes
- Security vulnerabilities: Security bulletins
1.33.13-gke.1721000
The following sections describe changes in this patch version when compared with the previous patch version, 1.33.13-gke.1647000. For information about upstream Kubernetes changes, see the Kubernetes v1.33.13 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
customer-logs-exporter
Updated customer-logs-exporter component from version 1.33.1-gke.21 to 1.33.1-gke.22.
- Miscellaneous:
- Updated the
bashbase image to a newer version.
- Updated the
filestorecsi
Updated filestorecsi component from version 0.18.43 to 0.18.44.
- Security Fixes:
- Updated Go dependencies to resolve CVE-2026-29181, CVE-2026-41178, CVE-2026-46600, CVE-2026-56852, CVE-2026-56854, CVE-2026-78662, GO-2026-5841, and GO-2026-6061.
- Miscellaneous:
- Updated the Go runtime and base container images (Debian and distroless-static) for the Filestore CSI driver and associated sidecars, including csi-provisioner, csi-resizer, csi-snapshotter, snapshot-controller, csi-node-driver-registrar, and csi-snapshot-validation-webhook.
gcsfusecsi
Updated gcsfusecsi component from version 0.10.72 to 0.10.74.
- Security Fixes:
- Updated google.golang.org/grpc to v1.83.1 and updated the csi-node-driver-registrar image to resolve CVE-2026-84304.
- Miscellaneous:
- Updated the Go runtime and container base images for the following components: gcs-fuse-csi-driver, csi-node-driver-registrar, gcs-fuse-csi-driver-sidecar-mounter, and gcs-fuse-csi-driver-metadata-prefetch.
gvisor
Updated gvisor component from version 1.33.5 to 1.33.8.
- Miscellaneous:
- Updated container images for node_token_broker/init and gke-distroless/static.
osimage
Updated osimage component from version 1.33.193 to 1.33.208.
- Features:
- Added opt-in support for the guest agent extensions manager, MWLID, and Telemetry extensions.
- Updated Linux kernel to COS-6.6.153.
- Updated Docker to v27.5.1.
- Updated Containerd to v2.0.10.
- Updated cos-gpu-installer to v2.7.7.
- Bug Fixes:
- Updated dev-lang/go to version 1.25.12.
- Resolved an issue in the XFS file system where direct I/O writes could utilize outdated block mappings during Copy-on-Write (CoW) operations.
- Fixed a
docker cpfailure that occurred when copying to or from containers using symlinked bind mounts.
- Security Fixes:
- Fixed CVE-2026-64561 in the Linux kernel.
- Fixed CVE-2026-64562 in the Linux kernel.
- Fixed CVE-2026-64572 in the Linux kernel.
- Fixed CVE-2026-64576 in the Linux kernel.
- Fixed CVE-2026-64579 in the Linux kernel.
- Fixed CVE-2026-64580 in the Linux kernel.
- Fixed CVE-2026-64597 in the Linux kernel.
- Fixed CVE-2026-64598 in the Linux kernel.
- Fixed CVE-2026-64604 in the Linux kernel.
- Fixed CVE-2026-68093 in the Linux kernel.
- Fixed CVE-2026-68116 in the Linux kernel.
- Fixed CVE-2026-68147 in the Linux kernel.
- Fixed CVE-2026-68184 in the Linux kernel.
- Fixed CVE-2026-68186 in the Linux kernel.
- Fixed CVE-2026-68187 in the Linux kernel.
- Fixed CVE-2026-68284 in the Linux kernel.
- Fixed CVE-2026-68325 in the Linux kernel.
- Fixed CVE-2026-68336 in the Linux kernel.
- Fixed CVE-2026-68338 in the Linux kernel.
- Fixed CVE-2026-68343 in the Linux kernel.
- Fixed CVE-2026-68386 in the Linux kernel.
- Fixed CVE-2026-68398 in the Linux kernel.
- Fixed CVE-2026-68425 in the Linux kernel.
- Fixed CVE-2026-68428 in the Linux kernel.
- Fixed CVE-2026-64279 in the Linux kernel.
- Fixed CVE-2026-64319 in the Linux kernel.
- Fixed CVE-2026-64352 in the Linux kernel.
- Fixed CVE-2026-64375 in the Linux kernel.
- Fixed CVE-2026-64401 in the Linux kernel.
- Fixed CVE-2026-64413 in the Linux kernel.
- Fixed CVE-2026-64474 in the Linux kernel.
- Fixed CVE-2026-64476 in the Linux kernel.
- Fixed CVE-2026-64535 in the Linux kernel.
- Fixed KCTF-8173f7e in the Linux kernel.
- Fixed CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, and CVE-2026-46598 in dev-go/crypto.
- Fixed CVE-2026-58470 in net-misc/wget.
- Fixed CVE-2026-59890 in dev-python/setuptools.
- Fixed the following CVEs in the Linux kernel: CVE-2026-64227, CVE-2026-64266, CVE-2026-64286, CVE-2026-64287, CVE-2026-64294, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64313, CVE-2026-64317, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64326, CVE-2026-64355, CVE-2026-64368, CVE-2026-64370, CVE-2026-64373, CVE-2026-64379, CVE-2026-64380, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64411, CVE-2026-64412, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64456, CVE-2026-64475, CVE-2026-64507, CVE-2026-64508, CVE-2026-64512, CVE-2026-64514, CVE-2026-64530, CVE-2026-64534, CVE-2026-64538, CVE-2026-64545, CVE-2026-64546, CVE-2026-64548, CVE-2026-64552, CVE-2026-64554, and CVE-2026-64556.
- Fixed CVE-2026-29111 in sys-apps/systemd.
- Fixed CVE-2026-35177 in app-editors/vim and app-editors/vim-core.
- Fixed CVE-2026-3644 and CVE-2026-6019 in dev-lang/python.
- Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.
- Fixed multiple vulnerabilities in the Linux kernel: CVE-2026-53381, CVE-2026-53385, CVE-2026-53388, CVE-2026-53391, CVE-2026-53397, CVE-2026-53398, CVE-2026-63794, CVE-2026-63795, CVE-2026-63800, CVE-2026-63802, CVE-2026-63807, CVE-2026-63809, CVE-2026-63823, CVE-2026-63824, CVE-2026-63827, CVE-2026-63828, CVE-2026-63830, CVE-2026-64244, and CVE-2026-64247.
- Fixed multiple vulnerabilities in openssh: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and CVE-2026-60002.
- Upgraded net-libs/nghttp2 to 1.69.0 and fixed CVE-2026-58055.
- Updated containerd to v2.0.10 to address CVE-2026-46680.
- Fixed CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, and CVE-2026-58016 in glib.
- Addressed Linux kernel vulnerabilities: CVE-2026-23278, CVE-2026-43010, CVE-2026-46135, CVE-2026-46331, CVE-2026-53163, and CVE-2026-53167.
- Fixed CVE-2026-58469, CVE-2026-58471, and CVE-2026-58472 in net-misc/wget.
- Fixed CVE-2026-40225 in sys-apps/systemd.
- Fixed CVE-2026-53362 in the Linux kernel.
- Fixed vulnerabilities in the Linux kernel: CVE-2026-64371, CVE-2026-68142, and CVE-2026-68432.
- Upgraded dev-libs/libxml2 to v2.15.3 to resolve CVE-2026-0989, CVE-2026-0990, and CVE-2026-0992.
- Updated system libraries and packages to resolve CVE-2026-6238 and CVE-2026-25680.
- Miscellaneous:
- OS image version updated to cos-121-18867-528-36.
- Upgraded net-misc/curl to version 8.21.0.
- Updated base image to cos-arm64-121-18867-528-10.
pdcsi
Updated pdcsi component from version 0.22.83 to 0.22.86.
- Security Fixes:
- Fixed security vulnerabilities CVE-2026-29181, CVE-2026-39883, CVE-2026-56853, CVE-2026-56865, and CVE-2026-39822 by upgrading PDCSI driver image to v1.20.4-gke.31.
- Updated Go modules to resolve security vulnerabilities: CVE-2026-84304, CVE-2026-84445, and CVE-2026-78662.
- Miscellaneous:
- Updated the Go runtime to version 1.27.1 and updated container base images for CSI sidecar components, including the node-driver-registrar, provisioner, resizer, and snapshotter.
workloadautoscaler
Updated workloadautoscaler component from version 16.14.0 to 16.15.0.
- Miscellaneous:
- Updated Vertical Pod Autoscaler components, including the admission controller, recommender, and updater, to version 0.24.0-gke.18.
1.33.13-gke.1647000
The following sections describe changes in this patch version when compared with the previous patch version, 1.33.13-gke.1636000. For information about upstream Kubernetes changes, see the Kubernetes v1.33.13 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
kube-addon-manager
Updated kube-addon-manager component from version 31.0.21 to 31.0.22.
- Miscellaneous:
- Updated the
gke-distroless/bashcontainer image to versiongke_distroless_20260815.00_p0.
- Updated the
1.33.13-gke.1636000
The following sections describe changes in this patch version when compared with the previous patch version, 1.33.13-gke.1613000. For information about upstream Kubernetes changes, see the Kubernetes v1.33.13 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
envoy
Updated envoy component from version 1.0.21 to 1.0.22.
- Security Fixes:
- Updated
kcp_envoyimage to include TCP connection pool pointer validation security fix.
- Updated
1.33.13-gke.1613000
The following sections describe changes in this patch version when compared with the previous patch version, 1.33.13-gke.1547000. For information about upstream Kubernetes changes, see the Kubernetes v1.33.13 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
advanceddatapath
Updated advanceddatapath component from version 33.7.45 to 33.7.46.
- Security Fixes:
- Updated
golang.org/x/netto resolve GO-2026-4440 and GO-2026-5942. - Updated
golang.org/x/textto resolve GO-2026-5970.
- Updated
- Miscellaneous:
- Updated Debian base images for various internal components.
gcsfusecsi
Updated gcsfusecsi component from version 0.10.71 to 0.10.72.
- Security Fixes:
- Fixed the following container CVEs: CVE-2024-45337, CVE-2026-27143, CVE-2026-33186, CVE-2026-39821, CVE-2026-39822, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508, and CVE-2026-46595.
tpu-device-plugin
Updated tpu-device-plugin component from version 1.33.22-gke.9 to 1.33.22-gke.10.
- Security Fixes:
- Updated
google.golang.org/grpcto v1.82.1 to resolve GO-2026-6061.
- Updated
1.33.13-gke.1547000
The following sections describe changes in this patch version when compared with the previous patch version, 1.33.13-gke.1499000. For information about upstream Kubernetes changes, see the Kubernetes v1.33.13 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
gcsfusecsi
Updated gcsfusecsi component from version 0.10.69 to 0.10.71.
- Security Fixes:
- Fixed the following container CVEs: CVE-2024-45337, CVE-2026-27143, CVE-2026-33186, CVE-2026-39821, CVE-2026-39822, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-42508, and CVE-2026-46595.
- Updated Go modules to address identified security vulnerabilities.
- Updated
csi-node-driver-registrarto versionv2.10.1-gke.91to incorporate security patches.
l7-lb-controller-combined
Updated l7-lb-controller-combined component from version 1.36.6-gke.1 to 1.36.7-gke.1.
- Features:
- Added support for NEG pre-provisioning via service annotations and a new feature flag.
- Introduced management of
NEGBindingCustom Resources by the NEG controller, including ownership tracking and status reporting. - Enhanced Standalone L4 NEG controller observability with new metrics for service counts, sync latency, and status conditions for better troubleshooting.
- Added support for Bring Your Own IPv6 (BYOIPv6) in Network Load Balancers (NetLB) via the
ip-collection-v6annotation. - Improved L4 Standalone NEG controller to support reading multiple IP addresses from Forwarding Rules.
- Updated Topology Provider to be multi-network aware when retrieving zone and subnet information.
- Bug Fixes:
- Resolved a worker goroutine leak in the NEG controller that resulted in significant CPU spikes.
- Fixed a nil pointer dereference panic in L4 NetLB occurring when
sessionAffinityConfigwas omitted from the service specification. - Improved L4 Address Manager validation by replacing unanchored regex matching with strict IP parsing to prevent false positive matches.
- Fixed a bug in the address deletion logic where a target IP was incorrectly used instead of the region.
- Implemented IPv6 address canonicalization and automated stripping of
/96prefixes from Forwarding Rule addresses to comply with strict Kubernetes API validation. - Fixed a flag collision between the Standalone NEG controller and L4 leader election.
- Added handling for "tombstone" objects in the provider configuration to prevent filtering errors during resource deletion.
- Ensured Service NEGs are available in the local lister immediately after creation and enabled parallel syncer execution for better performance.
- Security Fixes:
- Updated
golang.org/x/netto v0.56.0 to address known security vulnerabilities in transitive dependencies. - Sanitized INI values in Google Compute Engine provider configurations to prevent potential CRLF injection.
- Updated
- Miscellaneous:
- Optimized performance by retrieving specific Forwarding Rules instead of listing all rules when checking for address availability.
- Enforced a limit of 10 Forwarding Rules within the Standalone NEG Controller.
- Implemented
allowMissingsupport in FilteredInformers for the Node informer to improve controller robustness.