Google Cloud Linux Kernel Flaws Enable Privilege Escalation on Container Nodes
Google Cloud disclosed multiple high-severity Linux kernel vulnerabilities affecting Container-Optimized OS nodes. These flaws allow privilege escalation, risking control over container hosts. The bulletins also cover medium to high severity vulnerabilities in Envoy Proxy and Istio, components used in service mesh architectures.
Additionally, Vertex AI Experiments has a bucket naming flaw (CVE-2026-2473) that could let attackers pre-create buckets to execute cross-tenant remote code, steal models, or poison data. Google states no customer action is needed for this issue.