This document lists the changes for the patch versions of the Google Kubernetes Engine (GKE) 1.34 minor version.
These changelogs are supplementary information about the updates to specific GKE system components. For information about features, changes, and security issues in GKE, see the following documents:
- Product updates: GKE release notes
- Security vulnerabilities: Security bulletins
1.34.10-gke.1328000
The following sections describe changes in this patch version when compared with the previous patch version, 1.34.10-gke.1236000. For information about upstream Kubernetes changes, see the Kubernetes v1.34.10 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
accelerator-operator
Updated accelerator-operator component from version 1.34.10 to 1.34.11.
- Miscellaneous:
- Updated the accelerator-operator container image to version v1.34.5-gke.13.
customer-logs-exporter
Updated customer-logs-exporter component from version 1.34.0-gke.8 to 1.34.0-gke.9.
- Miscellaneous:
- Updated the
bashbase image used by the component.
- Updated the
gcsfusecsi
Updated gcsfusecsi component from version 1.34.58 to 1.34.59.
- Miscellaneous:
- Updated the Go runtime to version 1.25.14 and updated base images for the Google Cloud Storage Fuse CSI driver, node- driver-registrar, sidecar mounter, webhook, and metadata prefetcher.
osimage
Updated osimage component from version 1.34.181 to 1.34.197.
- Features:
- Enabled CONFIG_UDMABUF on x86_64 architectures.
- Added bpf-lsm-policy for VM restrictions.
- Updated Linux kernel to COS-6.12.94.
- Updated Docker to v27.5.1.
- Updated containerd to v2.1.9.
- Enabled
CONFIG_MEMORY_FAILUREin the Linux kernel for ARM64 to improve memory error handling when running CUDA workloads.
- Bug Fixes:
- Applied a kernel patch to reduce the bcache garbage collection sleep interval, preventing potential I/O stalls.
- Resolved a significant issue affecting users of the XFS file system.
- Updated the udev rule configuration for the
protected_stateful_partition. - Upgraded curl to 8.21.0.
- Changed the installation path for
google-guest-agentplugins to/var/lib/google/guest-agent.
- Security Fixes:
- Fixed CVE-2026-68329 in the Linux kernel.
- Fixed CVE-2026-64380 in the Linux kernel.
- Fixed CVE-2026-64561 in the Linux kernel.
- Fixed CVE-2026-64562 in the Linux kernel.
- Fixed CVE-2026-64567 in the Linux kernel.
- Fixed CVE-2026-64572 in the Linux kernel.
- Fixed CVE-2026-64576 in the Linux kernel.
- Fixed CVE-2026-64579 in the Linux kernel.
- Fixed CVE-2026-64580 in the Linux kernel.
- Fixed CVE-2026-64590 in the Linux kernel.
- Fixed CVE-2026-64593 in the Linux kernel.
- Fixed CVE-2026-64597 in the Linux kernel.
- Fixed CVE-2026-64598 in the Linux kernel.
- Fixed CVE-2026-64604 in the Linux kernel.
- Fixed CVE-2026-68092 in the Linux kernel.
- Fixed CVE-2026-68119 in the Linux kernel.
- Fixed CVE-2026-68136 in the Linux kernel.
- Fixed CVE-2026-68142 in the Linux kernel.
- Fixed CVE-2026-68145 in the Linux kernel.
- Fixed CVE-2026-68146 in the Linux kernel.
- Fixed CVE-2026-68147 in the Linux kernel.
- Fixed CVE-2026-68149 in the Linux kernel.
- Fixed CVE-2026-68184 in the Linux kernel.
- Fixed CVE-2026-68186 in the Linux kernel.
- Fixed CVE-2026-68187 in the Linux kernel.
- Fixed CVE-2026-68284 in the Linux kernel.
- Fixed CVE-2026-68338 in the Linux kernel.
- Fixed CVE-2026-68388 in the Linux kernel.
- Fixed CVE-2026-68396 in the Linux kernel.
- Fixed CVE-2026-68398 in the Linux kernel.
- Fixed CVE-2026-68422 in the Linux kernel.
- Fixed CVE-2026-68425 in the Linux kernel.
- Fixed CVE-2026-68428 in the Linux kernel.
- Fixed CVE-2026-68432 in the Linux kernel.
- Fixed CVE-2026-68442 in the Linux kernel.
- Fixed CVE-2026-68450 in the Linux kernel.
- Fixed CVE-2026-35177 in app-editors/vim and app-editors/vim-core.
- Fixed CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, and CVE-2026-46598 in dev-go/crypto.
- Fixed CVE-2026-58470 in net-misc/wget.
- Fixed CVE-2026-59890 in dev-python/setuptools.
- Fixed multiple vulnerabilities in the Linux kernel: CVE-2026-64227, CVE-2026-64244, CVE-2026-64247, CVE-2026-64265, CVE-2026-64266, CVE-2026-64284, CVE-2026-64289, CVE-2026-64294, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64313, CVE-2026-64317, CVE-2026-64319, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64326, CVE-2026-64354, CVE-2026-64357, CVE-2026-64368, CVE-2026-64370, CVE-2026-64373, CVE-2026-64378, CVE-2026-64379, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64411, CVE-2026-64412, CVE-2026-64414, CVE-2026-64415, CVE-2026-64418, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64432, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64456, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475, CVE-2026-64512, and CVE-2026-64514.
- Upgraded net-libs/nghttp2 to 1.69.0 to fix CVE-2026-58055.
- Fixed CVE-2026-29111 in sys-apps/systemd.
- Fixed CVE-2026-3644 and CVE-2026-6019 in dev-lang/python.
- Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.
- Fixed multiple vulnerabilities in the Linux kernel: CVE-2026-53381, CVE-2026-53385, CVE-2026-53388, CVE-2026-53391, CVE-2026-53392, CVE-2026-53393, CVE-2026-53394, CVE-2026-53397, CVE-2026-53398, CVE-2026-53400, CVE-2026-63795, CVE-2026-63800, CVE-2026-63802, CVE-2026-63806, CVE-2026-63807, CVE-2026-63809, CVE-2026-63810, CVE-2026-63823, CVE-2026-63824, CVE-2026-63827, CVE-2026-63828, CVE-2026-63829, CVE-2026-63830, CVE-2026-63833, CVE-2026-64187, and CVE-2026-64189.
- Fixed multiple vulnerabilities in openssh: CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and CVE-2026-60002.
- Fixed CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, and CVE-2026-58016 in glib.
- Fixed CVE-2026-43010 and CVE-2026-43216 in the Linux kernel.
- Fixed CVE-2026-58469, CVE-2026-58471, and CVE-2026-58472 in wget.
- Resolved CVE-2026-46680, CVE-2026-50195, CVE-2026-53492, and CVE-2026-53488 via containerd update to v2.1.9.
- Fixed CVE-2026-53341 in the Linux kernel.
- Fixed KCTF-736b380 in the Linux kernel.
- Miscellaneous:
- Synchronized OS image components with COS version 125-19216-532-25.
- Updated base image to cos-gb300-bm-125-19216-532-14.