Vulnerabilità ed exploit

COS Kernel Flaws Let Containers Reach the Host

Container-Optimized OS nodes are exposed to host-level compromise when a local attacker can turn a kernel bug into privilege escalation or container escape. The standard response of treating containers as a hard boundary misses that the node kernel sits underneath every workload on the host.

Google Cloud’s security bulletins flag two high-severity Linux kernel flaws on COS: CVE-2026-23351 and CVE-2026-31431. Google says CVE-2026-31431 lets an unprivileged local attacker write to the system page cache, which can lead to local privilege escalation and container escape.

The risk persists until node images are updated across the cluster. On COS, fixing the workload is not enough if the underlying node image still carries the vulnerable kernel.

1 fonte · 1 mag

CVE-2026-31431

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating… EPSS 3% (88º percentile). Patch Microsoft: CBL-Mariner Releases.

Data di correzione federale CISA 15 mag

CVE-2026-23351

NVD KEV

CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: split gc into unlink… EPSS 0.1% (3º percentile).

Cronologia

Fonti

Part of the PlainSec briefing for 2026-05-02

Every edition of this story: COS Kernel Flaws Let Containers Reach the Host

Altro da oggi