Vulnerabilities · 168 days ago
Google Cloud Linux Kernel Flaws Enable Privilege Escalation on Container Nodes Google Cloud disclosed multiple high-severity Linux kernel vulnerabilities affecting Container-Optimized OS nodes. These flaws allow privilege escalation, risking control over container hosts. The bulletins also cover medium to high severity vulnerabilities in Envoy Proxy and Istio, components used in service mesh architectures.
Additionally, Vertex AI Experiments has a bucket naming flaw (CVE-2026-2473 ) that could let attackers pre-create buckets to execute cross-tenant remote code, steal models, or poison data. Google states no customer action is needed for this issue.
CVEs in this update
332 CVEs
Across react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel, and related packages.
18 critical · 170 high · 117 medium · 9 low
20 in CISA KEV · 121 with EPSS above 1%
21 with functional or packaged public exploit code
Highest severity: CVE-2025-55182 · 10.0 CRITICAL
Highest EPSS: CVE-2021-22005 · 100%
Showing the top 10 by KEV, EPSS, and severity.
Timeline Mar 31 Reported by Google Cloud Security Bulletins Dec 12 CISA federal deadline for CVE-2025-55182 passedDec 5 CVE-2025-55182 added to CISA KEVOct 27 CISA federal deadline for CVE-2025-61882 passedOct 6 CVE-2025-61882 added to CISA KEVFeb 12 CISA federal deadline for CVE-2023-34048 passedJan 22 CVE-2023-34048 added to CISA KEVOct 31 CISA federal deadline for CVE-2023-44487 passedOct 10 CVE-2023-44487 added to CISA KEVOct 4 CISA federal deadline for CVE-2023-4863 passedSep 13 CVE-2023-4863 added to CISA KEVMay 3 CISA federal deadline for CVE-2021-34527 passedApr 27 CISA federal deadline for CVE-2021-3156 passedApr 6 CVE-2021-3156 added to CISA KEVNov 17 CISA federal deadline for CVE-2021-22005 passedNov 3 CVE-2021-22005 added to CISA KEVSources 1 source covering this story
Entities CVE-2025-55182 CVE-2025-61882 CVE-2023-44487 CVE-2023-4863 Part of the PlainSec briefing for 2026-04-03
Editions Related stories
Vulnerabilities · 168 days ago
Google Cloud Linux Kernel Flaws Enable Privilege Escalation on Container Nodes Google Cloud disclosed multiple high-severity Linux kernel vulnerabilities affecting Container-Optimized OS nodes. These flaws allow privilege escalation, risking control over container hosts. The bulletins also cover medium to high severity vulnerabilities in Envoy Proxy and Istio, components used in service mesh architectures.
Additionally, Vertex AI Experiments has a bucket naming flaw (CVE-2026-2473 ) that could let attackers pre-create buckets to execute cross-tenant remote code, steal models, or poison data. Google states no customer action is needed for this issue.
CVEs in this update
332 CVEs
Across react-server-dom-webpack, react-server-dom-turbopack, react-server-dom-parcel, and related packages.
18 critical · 170 high · 117 medium · 9 low
20 in CISA KEV · 121 with EPSS above 1%
21 with functional or packaged public exploit code
Highest severity: CVE-2025-55182 · 10.0 CRITICAL
Highest EPSS: CVE-2021-22005 · 100%
Showing the top 10 by KEV, EPSS, and severity.
Timeline Mar 31 Reported by Google Cloud Security Bulletins Dec 12 CISA federal deadline for CVE-2025-55182 passedDec 5 CVE-2025-55182 added to CISA KEVOct 27 CISA federal deadline for CVE-2025-61882 passedOct 6 CVE-2025-61882 added to CISA KEVFeb 12 CISA federal deadline for CVE-2023-34048 passedJan 22 CVE-2023-34048 added to CISA KEVOct 31 CISA federal deadline for CVE-2023-44487 passedOct 10 CVE-2023-44487 added to CISA KEVOct 4 CISA federal deadline for CVE-2023-4863 passedSep 13 CVE-2023-4863 added to CISA KEVMay 3 CISA federal deadline for CVE-2021-34527 passedApr 27 CISA federal deadline for CVE-2021-3156 passedApr 6 CVE-2021-3156 added to CISA KEVNov 17 CISA federal deadline for CVE-2021-22005 passedNov 3 CVE-2021-22005 added to CISA KEVSources 1 source covering this story
Entities CVE-2025-55182 CVE-2025-61882 CVE-2023-44487 CVE-2023-4863 Part of the PlainSec briefing for 2026-04-03
Editions Related stories