This document lists the changes for the patch versions of the Google Kubernetes Engine (GKE) 1.36 minor version.
These changelogs are supplementary information about the updates to specific GKE system components. For information about features, changes, and security issues in GKE, see the following documents:
- Product updates: GKE release notes
- Security vulnerabilities: Security bulletins
1.36.4-gke.1082000
The following sections describe changes in this patch version when compared with the previous patch version, 1.36.3-gke.1767000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.4 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
customer-logs-exporter
Updated customer-logs-exporter component from version 1.36.0-gke.9 to 1.36.0-gke.11.
- Security Fixes:
- Updated
google.golang.org/grpcto v1.82.1 to resolve GO-2026-6061.
- Updated
- Miscellaneous:
- Introduced new configuration support for cloud logging endpoints and project-specific metadata via
ComponentOptionsConfig.
- Introduced new configuration support for cloud logging endpoints and project-specific metadata via
gke-metrics-agent
Updated gke-metrics-agent component from version 2.136.18-gke.1 to 2.136.20-gke.0.
- Features:
- Implemented node-level Pressure Stall Information (PSI) collection.
- Miscellaneous:
- Optimized the container image size by adjusting vendor dependencies, reducing the image size from approximately 64MB to 47MB.
- Updated Workload Autoscaler to version 0.27.0-gke.17.
gvisor
Updated gvisor component from version 1.36.19 to 1.36.23.
- Miscellaneous:
- Updated gVisor to version 20260727.0_RC04.
l7-lb-controller-combined
Updated l7-lb-controller-combined component from version 1.41.1-gke.0 to 1.41.3-gke.0.
- Bug Fixes:
- Improved L4 Address Manager IP validation to prevent false positive substring matches and enforce explicit Network Tier and Load Balancing Scheme validation.
- Security Fixes:
- Go version update to 1.26.6, Go kubernetes client dependency updates to v1.36.3, update google.golang.org/api and google.golang.org/grpc to the newest versions.
osimage
Updated osimage component from version 1.36.75 to 1.36.95.
- Features:
- cchost: Added
bpf-lsm-policyfor enhanced VM restrictions. - Enabled CONFIG_UDMABUF on x86_64.
- Added support for net-fs/lustre-client-drivers v2.14.0_p259.
- Updated Linux kernel to COS-6.12.94.
- Updated Docker to v27.5.1.
- Updated Containerd to v2.2.6.
- Updated cos-gpu-installer to v2.7.7.
- cchost: Added
- Bug Fixes:
- Added a kernel patch to reduce the bcache garbage collection sleep interval, which prevents potential I/O stalls.
- Upgraded sys-apps/xemu to v0.0.10.
- Security Fixes:
- Fixed CVE-2026-64244, CVE-2026-64247, CVE-2026-64253, CVE-2026-64265, CVE-2026-64266, CVE-2026-64284, CVE-2026-64289, CVE-2026-64294, CVE-2026-64298, CVE-2026-64299, CVE-2026-64306, CVE-2026-64313, CVE-2026-64317, CVE-2026-64319, CVE-2026-64320, CVE-2026-64322, CVE-2026-64323, CVE-2026-64324, CVE-2026-64326, CVE-2026-64354, CVE-2026-64355, CVE-2026-64357, CVE-2026-64368, CVE-2026-64370, CVE-2026-64373, CVE-2026-64378, CVE-2026-64379, CVE-2026-64380, CVE-2026-64381, CVE-2026-64382, CVE-2026-64383, CVE-2026-64384, CVE-2026-64385, CVE-2026-64386, CVE-2026-64387, CVE-2026-64411, CVE-2026-64412, CVE-2026-64414, CVE-2026-64415, CVE-2026-64418, CVE-2026-64422, CVE-2026-64423, CVE-2026-64425, CVE-2026-64432, CVE-2026-64435, CVE-2026-64436, CVE-2026-64448, CVE-2026-64456, CVE-2026-64473, CVE-2026-64474, CVE-2026-64475, CVE-2026-64512, CVE-2026-64514, and CVE-2026-64556 in the Linux kernel.
- Fixed CVE-2026-39827, CVE-2026-39828, CVE-2026-39829, CVE-2026-39830, CVE-2026-39831, CVE-2026-39832, CVE-2026-39833, CVE-2026-39834, CVE-2026-39835, CVE-2026-42508, CVE-2026-46595, CVE-2026-46597, and CVE-2026-46598 in dev-go/crypto.
- Fixed CVE-2026-58055 by upgrading net-libs/nghttp2 to 1.69.0.
- Fixed CVE-2026-58470 in net-misc/wget.
- Fixed CVE-2026-59890 in dev-python/setuptools.
- Fixed CVE-2026-33186 in google-guest-agent.
- Fixed CVE-2026-64227 in the Linux kernel.
- Fixed CVE-2026-64279 in the Linux kernel.
- Fixed CVE-2026-64286 in the Linux kernel.
- Fixed CVE-2026-64287 in the Linux kernel.
- Fixed CVE-2026-64352 in the Linux kernel.
- Fixed CVE-2026-64375 in the Linux kernel.
- Fixed CVE-2026-64401 in the Linux kernel.
- Fixed CVE-2026-64413 in the Linux kernel.
- Fixed CVE-2026-64416 in the Linux kernel.
- Fixed CVE-2026-64476 in the Linux kernel.
- Fixed CVE-2026-64508 in the Linux kernel.
- Fixed CVE-2026-64530 in the Linux kernel.
- Fixed CVE-2026-64532 in the Linux kernel.
- Fixed CVE-2026-64533 in the Linux kernel.
- Fixed CVE-2026-64534 in the Linux kernel.
- Fixed CVE-2026-64535 in the Linux kernel.
- Fixed CVE-2026-64538 in the Linux kernel.
- Fixed CVE-2026-64542 in the Linux kernel.
- Fixed CVE-2026-64545 in the Linux kernel.
- Fixed CVE-2026-64546 in the Linux kernel.
- Fixed CVE-2026-64548 in the Linux kernel.
- Fixed CVE-2026-64552 in the Linux kernel.
- Fixed CVE-2026-64554 in the Linux kernel.
- Fixed CVE-2026-64555 in the Linux kernel.
- Fixed KCTF-8173f7e in the Linux kernel.
- Fixed CVE-2026-64561 in the Linux kernel.
- Fixed CVE-2026-64562 in the Linux kernel.
- Fixed CVE-2026-64567 in the Linux kernel.
- Fixed CVE-2026-64572 in the Linux kernel.
- Fixed CVE-2026-64576 in the Linux kernel.
- Fixed CVE-2026-64579 in the Linux kernel.
- Fixed CVE-2026-64590 in the Linux kernel.
- Fixed CVE-2026-64593 in the Linux kernel.
- Fixed CVE-2026-64597 in the Linux kernel.
- Fixed CVE-2026-64598 in the Linux kernel.
- Fixed CVE-2026-64604 in the Linux kernel.
- Fixed CVE-2026-68092 in the Linux kernel.
- Fixed CVE-2026-68093 in the Linux kernel.
- Fixed CVE-2026-68116 in the Linux kernel.
- Fixed CVE-2026-68119 in the Linux kernel.
- Fixed CVE-2026-68136 in the Linux kernel.
- Fixed CVE-2026-68139 in the Linux kernel.
- Fixed CVE-2026-68142 in the Linux kernel.
- Fixed CVE-2026-68145 in the Linux kernel.
- Fixed CVE-2026-68147 in the Linux kernel.
- Fixed CVE-2026-68149 in the Linux kernel.
- Fixed CVE-2026-68171 in the Linux kernel.
- Fixed CVE-2026-68184 in the Linux kernel.
- Fixed CVE-2026-68186 in the Linux kernel.
- Fixed CVE-2026-68187 in the Linux kernel.
- Fixed CVE-2026-68296 in the Linux kernel.
- Fixed CVE-2026-68299 in the Linux kernel.
- Fixed CVE-2026-68329 in the Linux kernel.
- Fixed CVE-2026-68336 in the Linux kernel.
- Fixed CVE-2026-68343 in the Linux kernel.
- Fixed CVE-2026-68386 in the Linux kernel.
- Fixed CVE-2026-68388 in the Linux kernel.
- Fixed CVE-2026-68396 in the Linux kernel.
- Fixed CVE-2026-68425 in the Linux kernel.
- Fixed CVE-2026-68428 in the Linux kernel.
- Fixed CVE-2026-68432 in the Linux kernel.
- Fixed CVE-2026-68442 in the Linux kernel.
- Fixed CVE-2026-68450 in the Linux kernel.
- Fixed CVE-2026-68284 in the Linux kernel.
- Fixed CVE-2026-68398 in the Linux kernel.
- Fixed CVE-2026-68096 in the Linux kernel.
- Fixed CVE-2026-68129 in the Linux kernel.
- Fixed CVE-2026-68146 in the Linux kernel.
- Fixed CVE-2026-68325 in the Linux kernel.
- Fixed CVE-2026-68338 in the Linux kernel.
- Fixed CVE-2026-68422 in the Linux kernel.
- Fixed KCTF-0650f1c in the Linux kernel.
- Miscellaneous:
- Adjusted runtime sysctl configuration for
net.ipv4.udp_mem. - Adjusted runtime sysctl
net.ipv4.udp_memsettings to optimize memory thresholds for UDP networking.
- Adjusted runtime sysctl configuration for
1.36.3-gke.1767000
The following sections describe changes in this patch version when compared with the previous patch version, 1.36.3-gke.1640000. For information about upstream Kubernetes changes, see the Kubernetes v1.36.3 changelog.
Component Updates
The following sections provide information about updates to specific GKE system components in this patch version.
clouddns
Updated clouddns component from version 36.3.2 to 36.3.3.
- Bug Fixes:
- Fix crash loop by mounting tmp as read-write in clouddns container.
gcsfusecsi
Updated gcsfusecsi component from version 1.36.38 to 1.36.41.
- Security Fixes:
- Updated
golang.org/x/modfrom v0.37.0 to v0.40.0 to address security vulnerability GO-2026-6179.
- Updated
networkpolicy-calico
Updated networkpolicy-calico component from version 4.36.0 to 4.36.1.
- Security Fixes:
- Fixed CVE-2026-39822 by updating the Go build version to 1.25.12.
- Updated
golang.org/x/cryptoto v0.52.0 to remediate security vulnerabilities in the Calico node component.