Vulnerabilità ed exploit

Google Cloud Linux Kernel Flaws Enable Privilege Escalation on Container Nodes

Google Cloud disclosed multiple high-severity Linux kernel vulnerabilities affecting Container-Optimized OS nodes. These flaws allow privilege escalation, risking control over container hosts. The bulletins also cover medium to high severity vulnerabilities in Envoy Proxy and Istio, components used in service mesh architectures.

Additionally, Vertex AI Experiments has a bucket naming flaw (CVE-2026-2473) that could let attackers pre-create buckets to execute cross-tenant remote code, steal models, or poison data. Google states no customer action is needed for this issue.

1 fonte · 31 mar

CVE in questo aggiornamento

332 CVE

Distribuite tra react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel e altri pacchetti correlati.

18 critiche · 170 alte · 117 medie · 9 basse

22 in CISA KEV · 122 con EPSS sopra 1%

21 con codice di exploit pubblico funzionante o integrato

Severità più alta: CVE-2025-55182 · 10.0 CRITICAL

EPSS più alto: CVE-2021-22005 · 100%

Mostriamo le prime 10 per KEV, EPSS e severità.

Cronologia

Fonti

Part of the PlainSec briefing for 2026-04-03

Every edition of this story: Google Cloud Linux Kernel Flaws Enable Privilege Escalation on Container Nodes

Altro da oggi