Vulnerabilities & Exploits

Linux Kernel Flaws Allow Privilege Escalation on Container Nodes

Google Cloud published multiple security bulletins for March 2026 describing high-severity Linux kernel vulnerabilities that can let an attacker escalate privileges on Container-Optimized OS nodes (examples include CVE-2025-38616, CVE-2026-23268, CVE-2025-38678). The bulletins also list Medium-to-High flaws in Envoy Proxy and Istio. Google disclosed a Vertex AI Experiments flaw (CVE-2026-2473) where predictable Cloud Storage bucket names could enable cross-tenant remote code execution, model theft, and poisoning, and said no customer action is required.

1 source · Mar 31

CVEs in this update

332 CVEs

Across react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel, and related packages.

18 critical · 170 high · 117 medium · 9 low

20 in CISA KEV · 121 with EPSS above 1%

21 with functional or packaged public exploit code

Highest severity: CVE-2025-55182 · 10.0 CRITICAL

Highest EPSS: CVE-2021-22005 · 100%

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

Part of the PlainSec briefing for 2026-03-31

Every edition of this story: Linux Kernel Flaws Allow Privilege Escalation on Container Nodes

More from today