This document lists the changes for the patch versions of the Google Kubernetes Engine (GKE) 1.35 minor version.
These changelogs are supplementary information about the updates to specific GKE system components. For information about features, changes, and security issues in GKE, see the following documents:
- Product updates: GKE release notes
- Security vulnerabilities: Security bulletins
1.35.8-gke.1036000
There are no customer-facing updates in this version when compared to the previous patch version, 1.35.8-gke.1026000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
1.35.8-gke.1026000
The following sections describe changes in this patch version when compared with the previous patch version, 1.35.7-gke.1222000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
advanceddatapath
Updated advanceddatapath component from version 35.3.22 to 35.3.23.
- Security Fixes:
- Updated
golang.org/x/netto address GO-2026-5942. - Updated
golang.org/x/textto address GO-2026-5970.
- Updated
customer-logs-exporter
Updated customer-logs-exporter component from version 1.35.1-gke.7 to 1.35.1-gke.8.
- Miscellaneous:
- Updated base image digests for the component.
gcsfusecsi
Updated gcsfusecsi component from version 1.35.55 to 1.35.58.
- Bug Fixes:
- Allow ToLocalhost egress in StaticPodNetworkPolicy for gcsfusecsi-controller to prevent SPNP firewall drops during local OAuth token exchange.
- Security Fixes:
- Fixed the following container CVEs: CVE-2026-27145, CVE-2026-39819, CVE-2026-39821, CVE-2026-39822, CVE-2026-39825, CVE-2026-39827, CVE-2026-39836, CVE-2026-46595, CVE-2026-46598, CVE-2026-46600, CVE-2026-56858, and CVE-2026-56860.
- Miscellaneous:
- Updated the Go runtime and base images for the CSI driver and its associated components, including the node driver registrar, sidecar mounter, webhook, and metadata prefetcher.
gpu-device-plugin
Updated gpu-device-plugin component from version 1.35.4-gke.4 to 1.35.5-gke.0.
- Security Fixes:
- Updated Ubuntu base images to 22.04 and 24.04 to address vulnerabilities.
networkpolicy-antrea
Updated networkpolicy-antrea component from version 0.6.8 to 0.6.9.
- Miscellaneous:
- Updated
cluster-proportional-autoscalerimage tov1.10.2-gke.54.
- Updated
networkpolicy-calico
Updated networkpolicy-calico component from version 4.35.3 to 4.35.4.
- Security Fixes:
- Fixed CVE-2026-39822 by updating the Go build version to 1.25.12.
- Updated
golang.org/x/cryptoto v0.52.0 to resolve security vulnerabilities incalico/node.
osimage
Updated osimage component from version 1.35.132 to 1.35.148.
- Features:
- Enabled CONFIG_UDMABUF on x86_64.
- Added
bpf-lsm-policyforcchostto implement VM restrictions. - Updated Linux kernel to COS-6.12.94.
- Enabled CONFIG_MEMORY_FAILURE in the Linux kernel for ARM64 to improve memory error handling for CUDA workloads.
- Bug Fixes:
- Added support for net-fs/lustre-client-drivers v2.14.0_p259.
- Upgraded sys-apps/xemu to v0.0.10.
- Updated cos-gpu-installer to v2.7.6.
- Applied a kernel patch to reduce the bcache garbage collection sleep interval, resolving a potential issue with I/O stalls.
- Resolved a critical bug impacting XFS file system users.
- Updated the udev rule for the protected stateful partition.
- Upgraded net-misc/curl to 8.21.0.
- Adjusted the google-guest-agent plugin installation path to /var/lib/google/guest-agent.
- Security Fixes:
- Fixed CVE-2026-68093 in the Linux kernel.
- Fixed CVE-2026-68096 in the Linux kernel.
- Fixed CVE-2026-68129 in the Linux kernel.
- Fixed CVE-2026-68296 in the Linux kernel.
- Fixed CVE-2026-68386 in the Linux kernel.
- Fixed KCTF-0650f1c in the Linux kernel.
- Fixed CVE-2026-68329 in the Linux kernel.
- Fixed CVE-2026-68116 in the Linux kernel.
- Fixed CVE-2026-68139 in the Linux kernel.
- Fixed CVE-2026-68171 in the Linux kernel.
- Fixed CVE-2026-68325 in the Linux kernel.
- Fixed CVE-2026-68336 in the Linux kernel.
- Fixed CVE-2026-68343 in the Linux kernel.
- Fixed CVE-2026-64380 in the Linux kernel.
- Fixed CVE-2026-64561 in the Linux kernel.
- Fixed CVE-2026-64562 in the Linux kernel.
- Fixed CVE-2026-64567 in the Linux kernel.
- Fixed CVE-2026-64572 in the Linux kernel.
- Fixed CVE-2026-64576 in the Linux kernel.
- Fixed CVE-2026-64579 in the Linux kernel.
- Fixed CVE-2026-64580 in the Linux kernel.
- Fixed CVE-2026-64590 in the Linux kernel.
- Fixed CVE-2026-64593 in the Linux kernel.
- Fixed CVE-2026-64597 in the Linux kernel.
- Fixed CVE-2026-64598 in the Linux kernel.
- Fixed CVE-2026-64604 in the Linux kernel.
- Fixed CVE-2026-68092 in the Linux kernel.
- Fixed CVE-2026-68119 in the Linux kernel.
- Fixed CVE-2026-68136 in the Linux kernel.
- Fixed CVE-2026-68142 in the Linux kernel.
- Fixed CVE-2026-68145 in the Linux kernel.
- Fixed CVE-2026-68146 in the Linux kernel.
- Fixed CVE-2026-68147 in the Linux kernel.
- Fixed CVE-2026-68149 in the Linux kernel.
- Fixed CVE-2026-68184 in the Linux kernel.
- Fixed CVE-2026-68186 in the Linux kernel.
- Fixed CVE-2026-68187 in the Linux kernel.
- Fixed CVE-2026-68284 in the Linux kernel.
- Fixed CVE-2026-68338 in the Linux kernel.
- Fixed CVE-2026-68388 in the Linux kernel.
- Fixed CVE-2026-68396 in the Linux kernel.
- Fixed CVE-2026-68398 in the Linux kernel.
- Fixed CVE-2026-68422 in the Linux kernel.
- Fixed CVE-2026-68425 in the Linux kernel.
- Fixed CVE-2026-68428 in the Linux kernel.
- Fixed CVE-2026-68432 in the Linux kernel.
- Fixed CVE-2026-68442 in the Linux kernel.
- Fixed CVE-2026-68450 in the Linux kernel.
- CVE-2026-35177: Fixed in
app-editors/vimandapp-editors/vim-core. - Fixed CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, and CVE-2026-46598 in
dev-go/crypto. - CVE-2026-58470: Fixed in
net-misc/wget. - CVE-2026-59890: Fixed in
dev-python/setuptools. - CVE-2026-58055: Fixed by upgrading
net-libs/nghttp2to 1.69.0. - Fixed multiple vulnerabilities in the Linux kernel: CVE-2026-64227, CVE-2026-64244, CVE-2026-64247, CVE-2026-64265, CVE-2026-64266, CVE-2026-64284, CVE-2026-64289, CVE-2026-64294, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64313, CVE-2026-64317, CVE-2026-64319, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64326, CVE-2026-64354, CVE-2026-64357, CVE-2026-64368, CVE-2026-64370, CVE-2026-64373, CVE-2026-64378, CVE-2026-64379, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64411, CVE-2026-64412, CVE-2026-64414, CVE-2026-64415, CVE-2026-64418, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64432, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64456, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475, CVE-2026-64512, and CVE-2026-64514.
- Fixed CVE-2026-29111 in sys-apps/systemd.
- Fixed CVE-2026-3644 and CVE-2026-6019 in dev-lang/python.
- Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.
- Fixed multiple vulnerabilities in the Linux kernel: CVE-2026-53381, CVE-2026-53385, CVE-2026-53388, CVE-2026-53391, CVE-2026-53392, CVE-2026-53393, CVE-2026-53394, CVE-2026-53397, CVE-2026-53398, CVE-2026-53400, CVE-2026-63795, CVE-2026-63800, CVE-2026-63802, CVE-2026-63806, CVE-2026-63807, CVE-2026-63809, CVE-2026-63810, CVE-2026-63823, CVE-2026-63824, CVE-2026-63827, CVE-2026-63828, CVE-2026-63829, CVE-2026-63830, CVE-2026-63833, CVE-2026-64187, and CVE-2026-64189.
- Fixed CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and CVE-2026-60002 in openssh.
- Fixed CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, and CVE-2026-58016 in glib.
- Fixed CVE-2026-43010 and CVE-2026-43216 in the Linux kernel.
- Fixed CVE-2026-58469, CVE-2026-58471, and CVE-2026-58472 in net-misc/wget.
- Updated containerd to v2.1.9 to resolve CVE-2026-46680, CVE-2026-50195, CVE-2026-53492, and CVE-2026-53488.
- Fixed CVE-2026-53341 in the Linux kernel.
- Fixed KCTF-736b380 in the Linux kernel.
- Miscellaneous:
- Modified runtime sysctl configuration for
net.ipv4.udp_mem. - Updated Docker runtime to v27.5.1.
- Updated containerd runtime to v2.2.7.
- Updated baseImage from cos-gb300-bm-125-19216-532-9 to cos-gb300-bm-125-19216-532-14.
- Modified runtime sysctl configuration for
tpu-device-plugin
Updated tpu-device-plugin component from version 1.35.13-gke.5 to 1.35.13-gke.6.
- Security Fixes:
- Updated
google.golang.org/grpcto v1.82.1 to address vulnerability GO-2026-6061.
- Updated