Google Cloud Issues Multiple Linux Kernel Privilege Escalation Fixes for GKE Nodes
Google Cloud published several security bulletins addressing High-severity Linux kernel vulnerabilities that allow privilege escalation on Container-Optimized OS nodes used in Google Kubernetes Engine (GKE). These include CVE-2026-23273, CVE-2025-38616, and CVE-2026-23268 among others. The patches target Google-managed node images rather than just upstream kernel versions, meaning operators must verify and update GKE node images and node pool versions specifically. Ubuntu GKE nodes also received updated patch guidance.
This coordinated patch rollup shifts the focus from generic Linux kernel patching to cloud provider image management. Operators who only patch upstream OS packages may miss these fixes. Delayed updates could leave nodes vulnerable to privilege escalation, so checking node image versions and applying Google-provided updates is critical.