GCP-2025-066
<p><strong>Published: </strong>2025-11-10<br/> <strong>Updated: </strong>2025-11-27<br/> <strong>Reference:</strong> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31133">CVE-2025-31133</a>, <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52565">CVE-2025-52565</a>, <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52881">CVE-2025-52881</a></p><p><strong>2025-11-27 Update: </strong> Added patch versions for GKE and GDC (bare metal).</p><devsite-selector> <section> <h3 data-text="GKE" id="gcp-2025-066-gke" tabindex="-1">GKE</h3> <p><strong>Updated: </strong>2025-11-27</p> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities.</p> <p>These vulnerabilities affect GKE Standard clusters running either Container-Optimized OS (COS) or Ubuntu node images, as well as Autopilot clusters. Node pools using GKE Sandbox are not affected and Windows node pools are not affected.</p> <h4 data-text="What should I do?" id="what-should-i-do_106" tabindex="-1">What should I do?</h4> <p><strong>2025-11-27 Update:</strong> The following versions of GKE are updated with code to fix these vulnerabilities on Container-Optimized OS. Upgrade your GKE node pools to the following versions or later: </p><ul> <li>1.34.1-gke.3355000</li> <li>1.33.5-gke.1791000</li> <li>1.32.9-gke.1548000</li> <li>1.31.13-gke.1454000</li> <li>1.30.14-gke.1719000</li> <li>1.29.15-gke.2467000</li> <li>1.28.15-gke.3163000</li> </ul> <p>The following GKE versions have been updated with code to fix these vulnerabilities on Ubuntu. Upgrade your GKE node pools to the following versions or later:</p> <ul> <li>1.33.5-gke.1791000</li> </ul> <p>You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/release-channels#newer-patch-versions">Run patch versions from a newer channel</a>.</p> <hr/> <p>GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available.</p> </td> <td>High</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GDC (VMware)" id="gcp-2025-066-gdcvmware" tabindex="-1">GDC (VMware)</h3> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities.</p> <p><strong>What should I do?</strong></p> <p>GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available.</p> </td> <td>High</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GKE on AWS" id="gcp-2025-066-gkeaws" tabindex="-1">GKE on AWS</h3> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities.</p> <p><strong>What should I do?</strong></p> <p>GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available.</p> </td> <td>High</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GKE on Azure" id="gcp-2025-066-gkeazure" tabindex="-1">GKE on Azure</h3> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities.</p> <p><strong>What should I do?</strong></p> <p>GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available.</p> </td> <td>High</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GDC (bare metal)" id="gcp-2025-066-gdcbm" tabindex="-1">GDC (bare metal)</h3> <p><strong>Updated: </strong>2025-11-27</p> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>Several security issues have been discovered in runc, an open source software component used for running containers on GKE. The vulnerabilities (CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881) allow an attacker to execute a full container breakout, leading to root privilege escalation on the host node. An actor with privileges to deploy a malicious container image can exploit these vulnerabilities.</p> <h4 data-text="What should I do?" id="what-should-i-do_107" tabindex="-1">What should I do?</h4> <p><strong>2025-11-27 Update: </strong>The following versions of GDC (bare metal) are updated with code to fix this vulnerability. Upgrade your GDC (bare metal) clusters to these versions or later:</p> <ul> <li>1.31.1000-gke.44</li> </ul> <hr/> <p>GKE is developing new versions that include the fixes for these vulnerabilities. This bulletin will be updated once these new versions are available.</p> </td> <td>High</td> </tr> </tbody> </table> </section> </devsite-selector>
Timeline
- Nov 10, 2025 CVE Published
References
- GCP-2025-066 (High) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31133 web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52565 web
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52881 web
- https://docs.cloud.google.com/kubernetes-engine/docs/concepts/release-channels#newer-patch-versions web