GCP-2026-015
<p><strong>Published: </strong>2026-03-27</p><h3 class="hide-from-toc" data-text="Description" id="description_6" tabindex="-1">Description</h3><table> <thead> <tr> <th width="70%">Description</th> <th>Severity</th> <th>Notes</th> </tr> </thead> <tbody> <tr> <td> <p>A vulnerability was discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes.</p> <h4 data-text="What should I do?" id="what-should-i-do_5" tabindex="-1">What should I do?</h4> <p>We recommend upgrading your Container-Optimized OS (COS) node to <code dir="ltr" translate="no">cos-125-19216-220-57</code>, which includes a fix for this vulnerability. For upgrade instructions, see one of the following:</p> <ul> <li>If you manage Container-Optimized OS VMs directly, then you should recreate your VMs by using the updated images. For more information, see <a href="https://cloud.google.com/compute/docs/instances/create-vm-from-public-image"> Creating a VM from a public image</a>.</li> <li>If you use Container-Optimized OS through a managed service (such as GKE, Dataflow, or Cloud SQL), then refer to the specific upgrade instructions for that service.</li> </ul> <p class="note"><strong>Note:</strong> Fixes are in progress for Container-Optimized OS milestones 117 and 121.</p> <h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_3" tabindex="-1">What vulnerabilities are being addressed?</h4> <p>The CrackArmor vulnerability in AppArmor, CVE-2026-23268, allows unprivileged users to bypass kernel protections, escalate to root, and break local container isolation.</p> </td> <td>High</td> <td> <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23268">CVE-2026-23268</a> </td> </tr> </tbody> </table>
Timeline
- Mar 27, 2026 CVE Published