This document lists the changes for the patch versions of the Google Kubernetes Engine (GKE) 1.35 minor version.
These changelogs are supplementary information about the updates to specific GKE system components. For information about features, changes, and security issues in GKE, see the following documents:
- Product updates: GKE release notes
- Security vulnerabilities: Security bulletins
1.35.8-gke.1796000
The following sections describe changes in this patch version when compared with the previous patch version, 1.35.8-gke.1626001. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
accelerator-operator
Updated accelerator-operator component from version 1.35.1 to 1.35.3.
- Security Fixes:
- Updated
go.opentelemetry.io/otel/sdkto v1.40.0 to address GO-2026-4394. - Updated
golang.org/x/netto v0.53.0 to address GO-2026-4440, GO-2026-4559, and GO-2026-4918. - Updated
google.golang.org/grpcto v1.79.3 to address GO-2026-4762.
- Updated
- Miscellaneous:
- Updated base images to use Golang 1.25.10.
- Backported CI/CD configurations, container build steps, and Go 1.25.0 toolchain fixes to the release branch.
- Updated the component image to version 1.35.0-gke.8.
filestorecsi
Updated filestorecsi component from version 1.35.28 to 1.35.30.
- Security Fixes:
- Updated Go modules
golang.org/x/cryptoandgoogle.golang.org/grpcto resolve CVE-2026-78662 and CVE-2026-84304.
- Updated Go modules
gcp-controller-manager-combined
Updated gcp-controller-manager-combined component from version 35.0.10 to 35.0.11.
- Miscellaneous:
- Updated the build configuration to disable CGO, eliminating runtime dependencies on gcc.
gcsfusecsi
Updated gcsfusecsi component from version 1.35.64 to 1.35.65.
- Security Fixes:
- Updated Go modules go.opentelemetry.io/otel and golang.org/x/crypto to resolve CVE-2026-41178 and CVE-2026-78662.
- Updated the container base image to address security vulnerabilities.
gpu-device-plugin
Updated gpu-device-plugin component from version 1.35.6-gke.0 to 1.35.6-gke.2.
- Security Fixes:
- Updated Go modules to address security vulnerabilities in gke-metrics-collector, nvidia-gpu-device-plugin, nvidia-partition-gpu, and nvidia-persistenced-installer.
- Miscellaneous:
- Updated container base images for nvidia-gpu-device-plugin, nvidia-partition-gpu, nvidia-persistenced-installer, and fastsocket-installer.
kubedns
Updated kubedns component from version 35.0.11 to 35.0.12.
- Security Fixes:
- Updated the Go build version and quic-go library to resolve CVE-2026-42507, CVE-2026-27145, CVE-2026-42504, and CVE-2026-40898.
- Miscellaneous:
- Updated the container base image to gke_distroless_20260901.00_p0.
- Updated Go module go.etcd.io/etcd/client/pkg/v3 from v3.6.10 to v3.6.14.
networkpolicy-antrea
Updated networkpolicy-antrea component from version 0.6.10 to 0.6.11.
- Bug Fixes:
- Added exponential backoff and retry for Windows named pipe connections in the Antrea agent. This addresses a race condition where the container runtime might attempt to connect to the CNI socket before it has been fully initialized during node boot, preventing transient "file not found" errors.
nodelocaldns
Updated nodelocaldns component from version 35.0.10 to 35.0.11.
- Miscellaneous:
- Updated go.etcd.io/etcd/client/pkg/v3 from v3.6.10 to v3.6.14.
pdcsi
Updated pdcsi component from version 1.35.52 to 1.35.54.
- Bug Fixes:
- Fixed an issue where access modes were handled incorrectly for Hyperdisk Balanced and Throughput volumes during retried
CreateVolumerequests.
- Fixed an issue where access modes were handled incorrectly for Hyperdisk Balanced and Throughput volumes during retried
- Security Fixes:
- Updated google.golang.org/grpc to resolve CVE-2026-84304 and CVE-2026-84445.
tpu-device-plugin
Updated tpu-device-plugin component from version 1.35.13-gke.8 to 1.35.13-gke.9.
- Bug Fixes:
- Stop emitting stale TPU runtime metrics after the last TPU container on a node exits. Replaces the periodic global
GaugeVec.Reset(which caused metric flip-flop in Prometheus) with stateful per-container tracking that deletes label values only after six consecutive missed collection cycles (~60 seconds).
- Stop emitting stale TPU runtime metrics after the last TPU container on a node exits. Replaces the periodic global
- Security Fixes:
- Updated
google.golang.org/grpcto v1.85.0-dev.0.20260825072537-93e31b48545e to address vulnerability GO-2026-6443. - Updated
golang.org/x/cryptofrom v0.53.0 to v0.56.0 to address vulnerabilities GO-2026-6303 and GO-2026-6354.
- Updated
- Miscellaneous:
- Bumped the Go builder base image to golang 1.26.8 to match the
godirective ingo.mod, unblocking the release image build. - Updated
gke-distroless/bashtogke_distroless_20260918.00_p0.
- Bumped the Go builder base image to golang 1.26.8 to match the
1.35.8-gke.1626001
There are no customer-facing updates in this version when compared to the previous patch version, 1.35.8-gke.1626000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
1.35.8-gke.1439001
There are no customer-facing updates in this version when compared to the previous patch version, 1.35.8-gke.1439000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
1.35.8-gke.1380001
There are no customer-facing updates in this version when compared to the previous patch version, 1.35.8-gke.1380000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
1.35.6-gke.1250001
There are no customer-facing updates in this version when compared to the previous patch version, 1.35.6-gke.1250000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.6 changelog.
1.35.8-gke.1626000
The following sections describe changes in this patch version when compared with the previous patch version, 1.35.8-gke.1439000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
filestorecsi
Updated filestorecsi component from version 1.35.27 to 1.35.28.
- Security Fixes:
- Updated Go dependencies to resolve CVE-2026-78662 and CVE-2026-84304.
- Miscellaneous:
- Updated the Go runtime to version 1.27.1 and updated container base images for CSI sidecar components including csi-provisioner, csi-resizer, and csi-snapshotter.
gcsfusecsi
Updated gcsfusecsi component from version 1.35.61 to 1.35.64.
- Security Fixes:
- Updated Go modules go.opentelemetry.io/otel and golang.org/x/crypto to resolve CVE-2026-41178 and CVE-2026-78662.
- Updated Go dependencies to address vulnerabilities CVE-2026-41178 and CVE-2026-78662.
- Miscellaneous:
- Updated the csi-node-driver-registrar image to v2.15.0-gke.47.
gvisor
Updated gvisor component from version 1.35.16 to 1.35.17.
- Miscellaneous:
- Updated the container base image to
gke_distroless_20260915.00_p0.
- Updated the container base image to
kube-addon-manager
Updated kube-addon-manager component from version 35.0.2 to 35.0.5.
- Features:
- Added support for multi-architecture releases.
- Miscellaneous:
- Updated the kubectl prune whitelist to include flow control resources (FlowSchema and PriorityLevelConfiguration) for clusters running Kubernetes 1.23.0 and newer.
- Added a configuration option to manage leader election modes for the addon manager.
managed-opentelemetry
Updated managed-opentelemetry component from version 1.35.13-gke.1 to 1.35.13-gke.2.
- Security Fixes:
- Upgraded otelcol-custom to 0.153.0-gke.5 to remediate golang.org/x/crypto CVEs.
osimage
Updated osimage component from version 1.35.152 to 1.35.160.
- Features:
- Enabled CONFIG_UDMABUF on x86_64.
- Added
bpf-lsm-policyforcchostto implement VM restrictions. - Enabled CONFIG_MEMORY_FAILURE in the Linux kernel for ARM64 to improve memory error handling for CUDA workloads.
- Added support for NVIDIA driver v595.91.07.
- Updated Linux kernel to COS-6.12.105.
- Updated Docker to v27.5.1.
- Updated Containerd to v2.2.7.
- Updated cos-gpu-installer to v2.7.6.
- Bug Fixes:
- Added support for net-fs/lustre-client-drivers v2.14.0_p259.
- Upgraded sys-apps/xemu to v0.0.10.
- Applied a kernel patch to reduce the bcache garbage collection sleep interval, resolving a potential issue with I/O stalls.
- Resolved a critical bug impacting XFS file system users.
- Updated the udev rule for the protected stateful partition.
- Upgraded net-misc/curl to 8.21.0.
- Adjusted the google-guest-agent plugin installation path to /var/lib/google/guest-agent.
- Resolved an issue where
docker cpfailed when copying to or from containers using symlinked bind mounts.
- Security Fixes:
- Fixed CVE-2026-68093 in the Linux kernel.
- Fixed CVE-2026-68096 in the Linux kernel.
- Fixed CVE-2026-68129 in the Linux kernel.
- Fixed CVE-2026-68296 in the Linux kernel.
- Fixed CVE-2026-68386 in the Linux kernel.
- Fixed KCTF-0650f1c in the Linux kernel.
- Fixed CVE-2026-68329 in the Linux kernel.
- Fixed CVE-2026-68116 in the Linux kernel.
- Fixed CVE-2026-68139 in the Linux kernel.
- Fixed CVE-2026-68171 in the Linux kernel.
- Fixed CVE-2026-68325 in the Linux kernel.
- Fixed CVE-2026-68336 in the Linux kernel.
- Fixed CVE-2026-68343 in the Linux kernel.
- Fixed CVE-2026-64380 in the Linux kernel.
- Fixed CVE-2026-64561 in the Linux kernel.
- Fixed CVE-2026-64562 in the Linux kernel.
- Fixed CVE-2026-64567 in the Linux kernel.
- Fixed CVE-2026-64572 in the Linux kernel.
- Fixed CVE-2026-64576 in the Linux kernel.
- Fixed CVE-2026-64579 in the Linux kernel.
- Fixed CVE-2026-64580 in the Linux kernel.
- Fixed CVE-2026-64590 in the Linux kernel.
- Fixed CVE-2026-64593 in the Linux kernel.
- Fixed CVE-2026-64597 in the Linux kernel.
- Fixed CVE-2026-64598 in the Linux kernel.
- Fixed CVE-2026-64604 in the Linux kernel.
- Fixed CVE-2026-68092 in the Linux kernel.
- Fixed CVE-2026-68119 in the Linux kernel.
- Fixed CVE-2026-68136 in the Linux kernel.
- Fixed CVE-2026-68142 in the Linux kernel.
- Fixed CVE-2026-68145 in the Linux kernel.
- Fixed CVE-2026-68146 in the Linux kernel.
- Fixed CVE-2026-68147 in the Linux kernel.
- Fixed CVE-2026-68149 in the Linux kernel.
- Fixed CVE-2026-68184 in the Linux kernel.
- Fixed CVE-2026-68186 in the Linux kernel.
- Fixed CVE-2026-68187 in the Linux kernel.
- Fixed CVE-2026-68284 in the Linux kernel.
- Fixed CVE-2026-68338 in the Linux kernel.
- Fixed CVE-2026-68388 in the Linux kernel.
- Fixed CVE-2026-68396 in the Linux kernel.
- Fixed CVE-2026-68398 in the Linux kernel.
- Fixed CVE-2026-68422 in the Linux kernel.
- Fixed CVE-2026-68425 in the Linux kernel.
- Fixed CVE-2026-68428 in the Linux kernel.
- Fixed CVE-2026-68432 in the Linux kernel.
- Fixed CVE-2026-68442 in the Linux kernel.
- Fixed CVE-2026-68450 in the Linux kernel.
- CVE-2026-35177: Fixed in
app-editors/vimandapp-editors/vim-core. - Fixed CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, and CVE-2026-46598 in
dev-go/crypto. - CVE-2026-58470: Fixed in
net-misc/wget. - CVE-2026-59890: Fixed in
dev-python/setuptools. - CVE-2026-58055: Fixed by upgrading
net-libs/nghttp2to 1.69.0. - Fixed multiple vulnerabilities in the Linux kernel: CVE-2026-64227, CVE-2026-64244, CVE-2026-64247, CVE-2026-64265, CVE-2026-64266, CVE-2026-64284, CVE-2026-64289, CVE-2026-64294, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64313, CVE-2026-64317, CVE-2026-64319, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64326, CVE-2026-64354, CVE-2026-64357, CVE-2026-64368, CVE-2026-64370, CVE-2026-64373, CVE-2026-64378, CVE-2026-64379, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64411, CVE-2026-64412, CVE-2026-64414, CVE-2026-64415, CVE-2026-64418, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64432, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64456, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475, CVE-2026-64512, and CVE-2026-64514.
- Fixed CVE-2026-29111 in sys-apps/systemd.
- Fixed CVE-2026-3644 and CVE-2026-6019 in dev-lang/python.
- Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.
- Fixed multiple vulnerabilities in the Linux kernel: CVE-2026-53381, CVE-2026-53385, CVE-2026-53388, CVE-2026-53391, CVE-2026-53392, CVE-2026-53393, CVE-2026-53394, CVE-2026-53397, CVE-2026-53398, CVE-2026-53400, CVE-2026-63795, CVE-2026-63800, CVE-2026-63802, CVE-2026-63806, CVE-2026-63807, CVE-2026-63809, CVE-2026-63810, CVE-2026-63823, CVE-2026-63824, CVE-2026-63827, CVE-2026-63828, CVE-2026-63829, CVE-2026-63830, CVE-2026-63833, CVE-2026-64187, and CVE-2026-64189.
- Fixed CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and CVE-2026-60002 in openssh.
- Fixed CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, and CVE-2026-58016 in glib.
- Fixed CVE-2026-43010 and CVE-2026-43216 in the Linux kernel.
- Fixed CVE-2026-58469, CVE-2026-58471, and CVE-2026-58472 in net-misc/wget.
- Updated containerd to v2.1.9 to resolve CVE-2026-46680, CVE-2026-50195, CVE-2026-53492, and CVE-2026-53488.
- Fixed CVE-2026-53341 in the Linux kernel.
- Fixed KCTF-736b380 in the Linux kernel.
- Updated sys-libs/glibc and dev-go/net to resolve CVE-2026-6238 and CVE-2026-25680.
- Miscellaneous:
- Modified runtime sysctl configuration for
net.ipv4.udp_mem. - Updated baseImage from cos-gb300-bm-125-19216-532-9 to cos-gb300-bm-125-19216-532-14.
- Adjusted the
net.ipv4.udp_memruntime sysctl value.
- Modified runtime sysctl configuration for
pdcsi
Updated pdcsi component from version 1.35.49 to 1.35.52.
- Bug Fixes:
- Fixed an issue where access modes were incorrectly handled for Hyperdisk Balanced and Hyperdisk Throughput volumes during retried CreateVolume calls.
- Security Fixes:
- Updated golang.org/x/crypto to v0.55.0 to resolve CVE-2026-56854.
- Updated
google.golang.org/grpcto resolve CVE-2026-84304.
- Miscellaneous:
- Updated the Go runtime and base container images to improve overall component stability.
workloadautoscaler
Updated workloadautoscaler component from version 18.10.0 to 18.11.0.
- Bug Fixes:
- Updated Vertical Pod Autoscaler components, including the admission-controller, recommender, and updater, to version 0.26.0-gke.18.
1.35.8-gke.1439000
The following sections describe changes in this patch version when compared with the previous patch version, 1.35.8-gke.1380000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
Kubernetes Updates
k8s-api
Updated k8s-api cohort from version 1.35.8-gke.100 to 1.35.8-gke.300.
- Miscellaneous:
- Added
GOMEMLIMITandGOGCenvironment variables to thekube-apiservermanifests to optimize memory usage and garbage collection behavior.
- Added
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
gcsfusecsi
Updated gcsfusecsi component from version 1.35.60 to 1.35.61.
- Miscellaneous:
- Updated Go runtime to 1.27.0, Debian base image to bookworm-v1.0.8-gke.10, and csi-node-driver-registrar to v2.15.0-gke.45.
l7-lb-controller-combined
Updated l7-lb-controller-combined component from version 1.38.7-gke.0 to 1.38.8-gke.0.
- Security Fixes:
- Added a validation check for Standalone L4 Network Endpoint Groups (NEGs) to verify proper attachment.
networkpolicy-antrea
Updated networkpolicy-antrea component from version 0.6.9 to 0.6.10.
- Miscellaneous:
- Updated Antrea image to v1.4.0-gke.73 and Cilium Windows image to v1.17.8-gke.134.
- Updated container base images and the Go runtime patch version.
tpu-device-plugin
Updated tpu-device-plugin component from version 1.35.13-gke.7 to 1.35.13-gke.8.
- Bug Fixes:
- Revert ACS Agent image to sha256:2c2cad2eff5811c906334bced6a00b6f938d4308a26921bab9f5fc7d7ef445fb to prevent synchronous informer cache sync stalls from blocking TPU device plugin registration and unblock Cluster Autoscaler qualification.
1.35.8-gke.1380000
The following sections describe changes in this patch version when compared with the previous patch version, 1.35.8-gke.1225000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
gcsfusecsi
Updated gcsfusecsi component from version 1.35.58 to 1.35.60.
- Bug Fixes:
- Update gcsfusecsi addon manager mode from Reconcile to Recreate to allow smooth deletion and recreation of immutable CSIDriver spec during rollouts and downgrades.
- Security Fixes:
- Fixed the following container CVEs: CVE-2026-27145, CVE-2026-39819, CVE-2026-39821, CVE-2026-39822, CVE-2026-39825, CVE-2026-39827, CVE-2026-39836, CVE-2026-46595, CVE-2026-46598, CVE-2026-46600, CVE-2026-56858, and CVE-2026-56860.
gpu-device-plugin
Updated gpu-device-plugin component from version 1.35.5-gke.0 to 1.35.6-gke.0.
- Miscellaneous:
- bump
gpu-device-plugintov1.35.5-gke.0 - bump
nvidia-partition-gputov1.35.5-gke.0 - bump
nvidia-persistenced-installertov1.35.5-gke.0
- bump
gvisor
Updated gvisor component from version 1.35.13 to 1.35.16.
- Miscellaneous:
- Updated the gke-distroless/static container base image.
- Updated gke-gvisor-installer to version 20260727.0_RC04.
pdcsi
Updated pdcsi component from version 1.35.48 to 1.35.49.
- Features:
- Added volume attach limits for n4d and n4a machine types.
- Bug Fixes:
- Fixed the btrfs CSI driver to correctly use the device path instead of the mount point for the
blkidargument.
- Fixed the btrfs CSI driver to correctly use the device path instead of the mount point for the
- Security Fixes:
- Updated Go modules to fix vulnerabilities: go.opentelemetry.io/otel to v1.44.0 (GO-2026-5158), go.opentelemetry.io/otel/sdk to v1.43.0 (GO-2026-5426), golang.org/x/crypto to v0.52.0 (GO-2026-5005), golang.org/x/mod to v0.40.0 (GO-2026-6179), golang.org/x/net to v0.56.0 (GO-2026-5942), golang.org/x/sys to v0.44.0 (GO-2026-5024), golang.org/x/text to v0.39.0 (GO-2026-5970), and google.golang.org/grpc to v1.82.1 (GO-2026-6061).
- Updated container base image to resolve multiple vulnerabilities: CVE-2019-9192, CVE-2026-39821, CVE-2026-39822, CVE-2026-39883, CVE-2026-5450, CVE-2026-56853, CVE-2026-56859, CVE-2026-56860, CVE-2026-56862, CVE-2026-56864, CVE-2026-56865, CVE-2019-1010023, CVE-2025-27587, CVE-2026-29181, CVE-2026-33818, CVE-2026-42505, CVE-2026-56858, and CVE-2026-6791.
- Miscellaneous:
- Added a user guide for dynamic volumes.
tpu-device-plugin
Updated tpu-device-plugin component from version 1.35.13-gke.6 to 1.35.13-gke.7.
- Features:
- Update ACS Agent image to include FatalErrorInfo and TPU Halt diagnostic collection.
1.35.8-gke.1225000
The following sections describe changes in this patch version when compared with the previous patch version, 1.35.8-gke.1036000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
osimage
Updated osimage component from version 1.35.148 to 1.35.152.
- Features:
- Updated Linux kernel to COS-6.12.94.
- Updated Docker to v27.5.1.
- Updated Containerd to v2.2.7.
- Updated cos-gpu-installer to v2.7.7.
- Bug Fixes:
- Added support for net-fs/lustre-client-drivers v2.14.0_p259.
- Upgraded sys-apps/xemu to v0.0.10.
- Security Fixes:
- Fixed CVE-2026-68093 in the Linux kernel.
- Fixed CVE-2026-68096 in the Linux kernel.
- Fixed CVE-2026-68129 in the Linux kernel.
- Fixed CVE-2026-68296 in the Linux kernel.
- Fixed CVE-2026-68386 in the Linux kernel.
- Fixed KCTF-0650f1c in the Linux kernel.
- Miscellaneous:
- Modified runtime sysctl configuration for
net.ipv4.udp_mem.
- Modified runtime sysctl configuration for
workloadautoscaler
Updated workloadautoscaler component from version 18.8.0 to 18.10.0.
- Miscellaneous:
- Updated Vertical Pod Autoscaler (VPA) admission-controller, recommender, and updater to version 0.26.0-gke.17.
1.35.8-gke.1036000
There are no customer-facing updates in this version when compared to the previous patch version, 1.35.8-gke.1026000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
1.35.8-gke.1026000
The following sections describe changes in this patch version when compared with the previous patch version, 1.35.7-gke.1222000. For information about upstream Kubernetes changes, see the Kubernetes v1.35.8 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
advanceddatapath
Updated advanceddatapath component from version 35.3.22 to 35.3.23.
- Security Fixes:
- Updated
golang.org/x/netto address GO-2026-5942. - Updated
golang.org/x/textto address GO-2026-5970.
- Updated
customer-logs-exporter
Updated customer-logs-exporter component from version 1.35.1-gke.7 to 1.35.1-gke.8.
- Miscellaneous:
- Updated base image digests for the component.
gcsfusecsi
Updated gcsfusecsi component from version 1.35.55 to 1.35.58.
- Bug Fixes:
- Allow ToLocalhost egress in StaticPodNetworkPolicy for gcsfusecsi-controller to prevent SPNP firewall drops during local OAuth token exchange.
- Security Fixes:
- Fixed the following container CVEs: CVE-2026-27145, CVE-2026-39819, CVE-2026-39821, CVE-2026-39822, CVE-2026-39825, CVE-2026-39827, CVE-2026-39836, CVE-2026-46595, CVE-2026-46598, CVE-2026-46600, CVE-2026-56858, and CVE-2026-56860.
- Miscellaneous:
- Updated the Go runtime and base images for the CSI driver and its associated components, including the node driver registrar, sidecar mounter, webhook, and metadata prefetcher.
gpu-device-plugin
Updated gpu-device-plugin component from version 1.35.4-gke.4 to 1.35.5-gke.0.
- Security Fixes:
- Updated Ubuntu base images to 22.04 and 24.04 to address vulnerabilities.
networkpolicy-antrea
Updated networkpolicy-antrea component from version 0.6.8 to 0.6.9.
- Miscellaneous:
- Updated
cluster-proportional-autoscalerimage tov1.10.2-gke.54.
- Updated
networkpolicy-calico
Updated networkpolicy-calico component from version 4.35.3 to 4.35.4.
- Security Fixes:
- Fixed CVE-2026-39822 by updating the Go build version to 1.25.12.
- Updated
golang.org/x/cryptoto v0.52.0 to resolve security vulnerabilities incalico/node.
osimage
Updated osimage component from version 1.35.132 to 1.35.148.
- Features:
- Enabled CONFIG_UDMABUF on x86_64.
- Added
bpf-lsm-policyforcchostto implement VM restrictions. - Updated Linux kernel to COS-6.12.94.
- Enabled CONFIG_MEMORY_FAILURE in the Linux kernel for ARM64 to improve memory error handling for CUDA workloads.
- Bug Fixes:
- Added support for net-fs/lustre-client-drivers v2.14.0_p259.
- Upgraded sys-apps/xemu to v0.0.10.
- Updated cos-gpu-installer to v2.7.6.
- Applied a kernel patch to reduce the bcache garbage collection sleep interval, resolving a potential issue with I/O stalls.
- Resolved a critical bug impacting XFS file system users.
- Updated the udev rule for the protected stateful partition.
- Upgraded net-misc/curl to 8.21.0.
- Adjusted the google-guest-agent plugin installation path to /var/lib/google/guest-agent.
- Security Fixes:
- Fixed CVE-2026-68093 in the Linux kernel.
- Fixed CVE-2026-68096 in the Linux kernel.
- Fixed CVE-2026-68129 in the Linux kernel.
- Fixed CVE-2026-68296 in the Linux kernel.
- Fixed CVE-2026-68386 in the Linux kernel.
- Fixed KCTF-0650f1c in the Linux kernel.
- Fixed CVE-2026-68329 in the Linux kernel.
- Fixed CVE-2026-68116 in the Linux kernel.
- Fixed CVE-2026-68139 in the Linux kernel.
- Fixed CVE-2026-68171 in the Linux kernel.
- Fixed CVE-2026-68325 in the Linux kernel.
- Fixed CVE-2026-68336 in the Linux kernel.
- Fixed CVE-2026-68343 in the Linux kernel.
- Fixed CVE-2026-64380 in the Linux kernel.
- Fixed CVE-2026-64561 in the Linux kernel.
- Fixed CVE-2026-64562 in the Linux kernel.
- Fixed CVE-2026-64567 in the Linux kernel.
- Fixed CVE-2026-64572 in the Linux kernel.
- Fixed CVE-2026-64576 in the Linux kernel.
- Fixed CVE-2026-64579 in the Linux kernel.
- Fixed CVE-2026-64580 in the Linux kernel.
- Fixed CVE-2026-64590 in the Linux kernel.
- Fixed CVE-2026-64593 in the Linux kernel.
- Fixed CVE-2026-64597 in the Linux kernel.
- Fixed CVE-2026-64598 in the Linux kernel.
- Fixed CVE-2026-64604 in the Linux kernel.
- Fixed CVE-2026-68092 in the Linux kernel.
- Fixed CVE-2026-68119 in the Linux kernel.
- Fixed CVE-2026-68136 in the Linux kernel.
- Fixed CVE-2026-68142 in the Linux kernel.
- Fixed CVE-2026-68145 in the Linux kernel.
- Fixed CVE-2026-68146 in the Linux kernel.
- Fixed CVE-2026-68147 in the Linux kernel.
- Fixed CVE-2026-68149 in the Linux kernel.
- Fixed CVE-2026-68184 in the Linux kernel.
- Fixed CVE-2026-68186 in the Linux kernel.
- Fixed CVE-2026-68187 in the Linux kernel.
- Fixed CVE-2026-68284 in the Linux kernel.
- Fixed CVE-2026-68338 in the Linux kernel.
- Fixed CVE-2026-68388 in the Linux kernel.
- Fixed CVE-2026-68396 in the Linux kernel.
- Fixed CVE-2026-68398 in the Linux kernel.
- Fixed CVE-2026-68422 in the Linux kernel.
- Fixed CVE-2026-68425 in the Linux kernel.
- Fixed CVE-2026-68428 in the Linux kernel.
- Fixed CVE-2026-68432 in the Linux kernel.
- Fixed CVE-2026-68442 in the Linux kernel.
- Fixed CVE-2026-68450 in the Linux kernel.
- CVE-2026-35177: Fixed in
app-editors/vimandapp-editors/vim-core. - Fixed CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, and CVE-2026-46598 in
dev-go/crypto. - CVE-2026-58470: Fixed in
net-misc/wget. - CVE-2026-59890: Fixed in
dev-python/setuptools. - CVE-2026-58055: Fixed by upgrading
net-libs/nghttp2to 1.69.0. - Fixed multiple vulnerabilities in the Linux kernel: CVE-2026-64227, CVE-2026-64244, CVE-2026-64247, CVE-2026-64265, CVE-2026-64266, CVE-2026-64284, CVE-2026-64289, CVE-2026-64294, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64313, CVE-2026-64317, CVE-2026-64319, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64326, CVE-2026-64354, CVE-2026-64357, CVE-2026-64368, CVE-2026-64370, CVE-2026-64373, CVE-2026-64378, CVE-2026-64379, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64411, CVE-2026-64412, CVE-2026-64414, CVE-2026-64415, CVE-2026-64418, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64432, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64456, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475, CVE-2026-64512, and CVE-2026-64514.
- Fixed CVE-2026-29111 in sys-apps/systemd.
- Fixed CVE-2026-3644 and CVE-2026-6019 in dev-lang/python.
- Fixed CVE-2026-40355 and CVE-2026-40356 in app-crypt/mit-krb5.
- Fixed multiple vulnerabilities in the Linux kernel: CVE-2026-53381, CVE-2026-53385, CVE-2026-53388, CVE-2026-53391, CVE-2026-53392, CVE-2026-53393, CVE-2026-53394, CVE-2026-53397, CVE-2026-53398, CVE-2026-53400, CVE-2026-63795, CVE-2026-63800, CVE-2026-63802, CVE-2026-63806, CVE-2026-63807, CVE-2026-63809, CVE-2026-63810, CVE-2026-63823, CVE-2026-63824, CVE-2026-63827, CVE-2026-63828, CVE-2026-63829, CVE-2026-63830, CVE-2026-63833, CVE-2026-64187, and CVE-2026-64189.
- Fixed CVE-2026-59995, CVE-2026-59996, CVE-2026-59997, CVE-2026-59999, CVE-2026-60000, CVE-2026-60001, and CVE-2026-60002 in openssh.
- Fixed CVE-2026-58013, CVE-2026-58014, CVE-2026-58015, and CVE-2026-58016 in glib.
- Fixed CVE-2026-43010 and CVE-2026-43216 in the Linux kernel.
- Fixed CVE-2026-58469, CVE-2026-58471, and CVE-2026-58472 in net-misc/wget.
- Updated containerd to v2.1.9 to resolve CVE-2026-46680, CVE-2026-50195, CVE-2026-53492, and CVE-2026-53488.
- Fixed CVE-2026-53341 in the Linux kernel.
- Fixed KCTF-736b380 in the Linux kernel.
- Miscellaneous:
- Modified runtime sysctl configuration for
net.ipv4.udp_mem. - Updated Docker runtime to v27.5.1.
- Updated containerd runtime to v2.2.7.
- Updated baseImage from cos-gb300-bm-125-19216-532-9 to cos-gb300-bm-125-19216-532-14.
- Modified runtime sysctl configuration for
tpu-device-plugin
Updated tpu-device-plugin component from version 1.35.13-gke.5 to 1.35.13-gke.6.
- Security Fixes:
- Updated
google.golang.org/grpcto v1.82.1 to address vulnerability GO-2026-6061.
- Updated