Vulnerabilities · 136 days ago

COS Kernel Flaws Let Containers Reach the Host

Container-Optimized OS nodes are exposed to host-level compromise when a local attacker can turn a kernel bug into privilege escalation or container escape. The standard response of treating containers as a hard boundary misses that the node kernel sits underneath every workload on the host.

Google Cloud’s security bulletins flag two high-severity Linux kernel flaws on COS: CVE-2026-23351 and CVE-2026-31431. Google says CVE-2026-31431 lets an unprivileged local attacker write to the system page cache, which can lead to local privilege escalation and container escape.

The risk persists until node images are updated across the cluster. On COS, fixing the workload is not enough if the underlying node image still carries the vulnerable kernel.

CVE-2026-31431

NVD KEV

Known exploited · CISA KEV

CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating… EPSS 100% (100th percentile). Microsoft patch: CBL-Mariner Releases.

CISA federal remediation date May 15

CVE-2026-23351

NVD KEV

CVSS 7.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: split gc into unlink… EPSS 0.1% (3rd percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-05-02

Editions

Related stories