GCP-2025-071
<p><strong>Published: </strong>2025-12-02<br/> <strong>Updated: </strong>2026-03-25<br/> <strong>Reference:</strong> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-40019">CVE-2025-40019</a></p><p><strong>2026-03-25 Update: </strong> Added patch versions for Ubuntu nodes with GKE.</p><p><strong>2025-12-11 Update: </strong> Added patch versions and a severity rating for GDC (VMware).</p><devsite-selector> <section> <h3 data-text="GKE" id="gcp-2025-071-gke" tabindex="-1">GKE</h3> <p><strong>Updated: </strong>2026-03-25</p> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: </p><ul> <li>CVE-2025-40019</li> </ul> <p>GKE Standard and Autopilot clusters are impacted.</p> <p>Clusters using <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/sandbox-pods">GKE Sandbox</a> aren't impacted.</p> <h4 data-text="What should I do?" id="what-should-i-do_96" tabindex="-1">What should I do?</h4> <p><strong>2026-03-25 Update</strong>: The following versions of GKE are updated with code to fix this vulnerability on Ubuntu. Upgrade your Ubuntu node pools to the following versions or later:</p> <ul> <li>1.35.1-gke.1396000</li> <li>1.34.4-gke.1047000</li> <li>1.33.8-gke.1026000</li> <li>1.32.12-gke.1026000</li> <li>1.31.14-gke.1476000</li> <li>1.30.14-gke.2117000</li> </ul> <hr/> <p>The following minor versions are affected. <a href="https://docs.cloud.google.com/kubernetes-engine/docs/how-to/upgrading-a-container-cluster">Upgrade</a> your Container-Optimized OS node pools to one of the following patch versions or later:</p> <ul> <li>1.28.15-gke.2966000</li><li>1.32.9-gke.1330000</li><li>1.33.5-gke.1350000</li><li>1.29.15-gke.2236000</li><li>1.31.13-gke.1231000</li><li>1.30.14-gke.1525000</li><li>1.34.1-gke.2541000</li> </ul> <p>You can apply patch versions from newer release channels if your cluster runs the same minor version in its own release channel. This feature lets you secure your nodes until the patch version becomes the default in your release channel. For details, see <a href="https://docs.cloud.google.com/kubernetes-engine/docs/concepts/release-channels#newer-patch-versions">Run patch versions from a newer channel</a>.</p> </td> <td>High</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GDC (VMware)" id="gcp-2025-071-gdcvmware" tabindex="-1">GDC (VMware)</h3> <p><strong>Updated: </strong>2025-12-11</p> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: </p><ul> <li>CVE-2025-40019</li> </ul> <h4 data-text="What should I do?" id="what-should-i-do_97" tabindex="-1">What should I do?</h4> <p>The following versions of GDC (VMware) are updated with code to fix this vulnerability. Upgrade your GDC (VMware) clusters to the following versions or later:</p> <ul> <li>1.31.1100-gke.40</li> </ul> <hr/> <p><aside class="note"><strong>Note: </strong>Patch versions and a severity assessment for GDC software for VMware are in progress. We'll update this bulletin with that information when it's available.</aside></p> </td> <td>High</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GKE on AWS" id="gcp-2025-071-gkeaws" tabindex="-1">GKE on AWS</h3> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: </p><ul> <li>CVE-2025-40019</li> </ul> <h4 data-text="What should I do?" id="what-should-i-do_98" tabindex="-1">What should I do?</h4> <p><aside class="note"><strong>Note: </strong>Patch versions and a severity assessment for GKE on AWS are in progress. We'll update this bulletin with that information when it's available.</aside></p> </td> <td>Pending</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GKE on Azure" id="gcp-2025-071-gkeazure" tabindex="-1">GKE on Azure</h3> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: </p><ul> <li>CVE-2025-40019</li> </ul> <h4 data-text="What should I do?" id="what-should-i-do_99" tabindex="-1">What should I do?</h4> <p><aside class="note"><strong>Note: </strong>Patch versions and a severity assessment for GKE on Azure are in progress. We'll update this bulletin with that information when it's available.</aside></p> </td> <td>Pending</td> </tr> </tbody> </table> </section> <section> <h3 data-text="GDC (bare metal)" id="gcp-2025-071-gdcbm" tabindex="-1">GDC (bare metal)</h3> <table> <thead> <tr> <th>Description</th> <th>Severity</th> </tr> </thead> <tbody> <tr> <td> <p>The following vulnerabilities were discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes: </p><ul> <li>CVE-2025-40019</li> </ul> <h4 data-text="What should I do?" id="what-should-i-do_100" tabindex="-1">What should I do?</h4> <p>There is no action required. GDC software for bare metal isn't affected as it does not bundle an operating system in its distribution.</p> </td> <td>None</td> </tr> </tbody> </table> </section> </devsite-selector>
Timeline
- Dec 2, 2025 CVE Published
References
- GCP-2025-071 (High) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-40019 web
- https://docs.cloud.google.com/kubernetes-engine/docs/concepts/sandbox-pods web
- https://docs.cloud.google.com/kubernetes-engine/docs/how-to/upgrading-a-container-cluster web
- https://docs.cloud.google.com/kubernetes-engine/docs/concepts/release-channels#newer-patch-versions web