Vulnerabilità · 151 giorni fa

COS Kernel Flaws Let Containers Reach the Host

Container-Optimized OS nodes are exposed to host-level compromise when a local attacker can turn a kernel bug into privilege escalation or container escape. The standard response of treating containers as a hard boundary misses that the node kernel sits underneath every workload on the host.

Google Cloud’s security bulletins flag two high-severity Linux kernel flaws on COS: CVE-2026-23351 and CVE-2026-31431. Google says CVE-2026-31431 lets an unprivileged local attacker write to the system page cache, which can lead to local privilege escalation and container escape.

The risk persists until node images are updated across the cluster. On COS, fixing the workload is not enough if the underlying node image still carries the vulnerable kernel.

CVE-2026-31431

NVD KEV

Sfruttamento noto · CISA KEV

CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating… EPSS 3% (88º percentile). Patch Microsoft: CBL-Mariner Releases.

Data di correzione federale CISA 15 mag

CVE-2026-23351

NVD KEV

CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: split gc into unlink… EPSS 0.1% (3º percentile).

Cronologia

Fonti

1 fonte che coprono questa storia

Entità

Part of the PlainSec briefing for 2026-05-02

Editions

Storie correlate