Vulnerabilities & Exploits

Google Cloud Linux Kernel Flaws Enable Privilege Escalation on Container Nodes

Google Cloud disclosed multiple high-severity Linux kernel vulnerabilities affecting Container-Optimized OS nodes. These flaws allow privilege escalation, risking control over container hosts. The bulletins also cover medium to high severity vulnerabilities in Envoy Proxy and Istio, components used in service mesh architectures.

Additionally, Vertex AI Experiments has a bucket naming flaw (CVE-2026-2473) that could let attackers pre-create buckets to execute cross-tenant remote code, steal models, or poison data. Google states no customer action is needed for this issue.

1 source · Mar 31

CVEs in this update

332 CVEs

Across react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel, and related packages.

18 critical · 170 high · 117 medium · 9 low

20 in CISA KEV · 121 with EPSS above 1%

21 with functional or packaged public exploit code

Highest severity: CVE-2025-55182 · 10.0 CRITICAL

Highest EPSS: CVE-2021-22005 · 100%

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

Part of the PlainSec briefing for 2026-04-03

Every edition of this story: Google Cloud Linux Kernel Flaws Enable Privilege Escalation on Container Nodes

More from today