<?xml version="1.0" encoding="UTF-8"?>
<!-- AUTOGENERATED FILE. DO NOT EDIT. -->
<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:cos-release-notes</id>
  <title>Container Optimized OS - Release notes</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/cos-release-notes.xml"/>
  <author>
    <name>Google Cloud Platform</name>
  </author>
  <updated>2026-06-08T00:00:00-07:00</updated>

  <entry>
    <title>June 08, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#June_08_2026</id>
    <updated>2026-06-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#June_08_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-395-73_">cos-125-19216-395-73 <a id='"cos-arm64-125-19216-395-73"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/9b2019e2a0a65bafcc7fb941120bfa3088ef8a59
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.73/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43492 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43499 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43503 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45837 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45838 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45839 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45841 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45842 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45843 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45844 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45987 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45991 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45997 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46005 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46015 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46021 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46051 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46061 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46062 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46065 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46070 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46072 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46076 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46082 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46089 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46094 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46101 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46102 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46106 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46108 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46115 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46120 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46124 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46128 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46129 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46132 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46139 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46149 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46150 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46155 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46159 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46172 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46173 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46174 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46177 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46193 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46195 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46196 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46209 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46300 in the Linux kernel.</p>
<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-129-19506-224-16_">cos-129-19506-224-16 <a id='"cos-arm64-129-19506-224-16"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e06aec09f8bd1eace9b1d1adb0ec84899e9a05f5
">COS-6.12.90</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.224.16/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-162_">cos-121-18867-381-162 <a id='"cos-arm64-121-18867-381-162"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3d2eca1b468c707fe3702ad6e28719c31d6176b1
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.162/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
]]>
    </content>
  </entry>

  <entry>
    <title>June 04, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#June_04_2026</id>
    <updated>2026-06-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#June_04_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-161_">cos-121-18867-381-161 <a id='"cos-arm64-121-18867-381-161"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3d2eca1b468c707fe3702ad6e28719c31d6176b1
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.161/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43499 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43503 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45838 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45839 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45841 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45842 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45843 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45844 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45987 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45991 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45997 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46005 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46015 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46021 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46051 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46065 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46070 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46082 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46089 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46094 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46101 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46102 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46106 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46115 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46120 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46124 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46132 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46149 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46150 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46155 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46172 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46173 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46174 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46195 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46196 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46209 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46300 in the Linux kernel.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-613-40_">cos-117-18613-613-40 <a id='"cos-arm64-117-18613-613-40"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8b4d5a73b054b07c3abedde85bd34343fffb9566
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.40/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated minijail to r188.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43499 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45838 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45839 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45841 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45842 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45843 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45844 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45987 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45991 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-45997 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46005 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46015 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46021 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46033 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46051 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46065 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46070 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46082 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46089 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46094 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46101 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46102 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46106 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46115 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46120 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46124 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46131 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46132 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46149 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46150 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46155 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46172 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46173 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46174 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46185 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46195 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46196 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46209 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46300 in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>June 01, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#June_01_2026</id>
    <updated>2026-06-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#June_01_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-148_">cos-121-18867-381-148 <a id='"cos-arm64-121-18867-381-148"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6c119c63599291cd468409254669be8082f330b9
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.148/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added dev-libs/mpdecimal and dev-python/gentoo-common.</p>
<h3>Change</h3>
<p>Updated app-containers/runc from v1.2.8 to v1.2.9</p>
<h3>Change</h3>
<p>Updated dev-lang/python to v3.11.15.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-395-55_">cos-125-19216-395-55 <a id='"cos-arm64-125-19216-395-55"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/d2ec5b118f6f5f38bb03d3079965327c76256ba1
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.55/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Allow overriding IMA policy from oem partition.</p>
<h3>Change</h3>
<p>On cchost boards, autoload IMA policy on boot.</p>
<h3>Change</h3>
<p>Set static UUID for the stateful partition.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-613-29_">cos-117-18613-613-29 <a id='"cos-arm64-117-18613-613-29"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/4c8dd0401cd7357d11e75a8467d834167db03513
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.29/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated Python to v3.8.20.</p>
<h3>Change</h3>
<p>Updated app-containers/runc from v1.2.8 to v1.2.9</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-129-19506-224-7_">cos-129-19506-224-7 <a id='"cos-arm64-129-19506-224-7"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ee5c0e72ce4f921969d64843af4f37b1e22a9738
">COS-6.12.90</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.224.7/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.04.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 26, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#May_26_2026</id>
    <updated>2026-05-26T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_26_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-129-19506-120-115_">cos-129-19506-120-115 <a id='"cos-arm64-129-19506-120-115"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/4b67db877bccca1607f98ab4fd34f80e6245828f
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.115/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Added support for the <code>swiotlb=any</code> kernel command line parameter.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Change</h3>
<p>Upgraded net-misc/openssh to v10.0_p2.</p>
<h3>Fixed</h3>
<p>Fixed a crash that occurs when using the <code>configfile</code> or
<code>source</code> GRUB2 commands when Secure Boot is enabled.</p>
<h3>Fixed</h3>
<p>Fixed a race condition triggered by ext4 online resize that
rarely causes machines to fail to boot.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31419 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31430 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43074 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43088 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-32289,CVE-2026-32282,CVE-2026-32288,CVE-2026-27142,CVE-2025-61728,CVE-2026-27139,CVE-2026-39817,CVE-2026-39819,CVE-2025-68119,CVE-2025-61732,CVE-2026-32280,CVE-2026-25679,CVE-2026-27144,CVE-2026-32283,CVE-2026-27140,CVE-2025-61731,CVE-2026-32281,CVE-2025-61726,CVE-2025-68121,CVE-2026-27143,CVE-2026-39826,CVE-2026-39823,CVE-2026-39825,CVE-2026-33814,CVE-2026-39820,CVE-2026-42499,CVE-2026-39836.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-395-47_">cos-125-19216-395-47 <a id='"cos-arm64-125-19216-395-47"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/b82d4fb79da9ccb0fb216da3a51f977397f3193d
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.47/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Added support for the <code>swiotlb=any</code> kernel command line parameter.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Upgrade app-admin/fluent-bit to v3.2.10</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Change</h3>
<p>Upgraded net-misc/openssh to v10.0_p2.</p>
<h3>Fixed</h3>
<p>Fixed a crash that occurs when using the <code>configfile</code> or
<code>source</code> GRUB2 commands when Secure Boot is enabled.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31419 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43088 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-42499,CVE-2026-39820,CVE-2026-39826,CVE-2026-33814,CVE-2026-39836,CVE-2026-39823,CVE-2026-39825,CVE-2026-39817,CVE-2026-39819.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-144_">cos-121-18867-381-144 <a id='"cos-arm64-121-18867-381-144"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/49ca470354b8180a68a948c2512fb9b5f4ef8b5f
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.144/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Upgrade app-admin/fluent-bit to v3.2.10</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23473 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43109 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-33814,CVE-2026-39823,CVE-2026-39826,CVE-2026-39817,CVE-2026-39819,CVE-2026-39820,CVE-2026-39836,CVE-2026-42499,CVE-2026-39825.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-613-25_">cos-117-18613-613-25 <a id='"cos-arm64-117-18613-613-25"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6cd389d7730d16d15e008a822b46e2f5d450d562
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.31</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.25/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This update contains several package upgrades to the latest patch version to ensure security, along with package patches for known CVEs.</p>
<h3>Change</h3>
<p>Update sys-process/audit to v3.0.9.</p>
<h3>Change</h3>
<p>Updated glib to v2.86.5.</p>
<h3>Change</h3>
<p>Updated sys-libs/pam to v1.5.3.</p>
<h3>Change</h3>
<p>Upgraded app-containers/containerd from v1.7.29 to
v1.7.31.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23171 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23473 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43109 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-44431 in dev-python/urllib3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-6732 in dev-libs/libxml2.</p>
<h3>Security</h3>
<p>Fixed KCTF-9e6bf14 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-lang/go to 1.25.10. This fixes CVE-2026-39817,CVE-2026-39825,CVE-2026-33814,CVE-2026-39819,CVE-2026-39826,CVE-2026-39823,CVE-2026-39820,CVE-2026-42499,CVE-2026-39836.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.20. This fixes CVE-2026-5545,CVE-2026-4873,CVE-2026-6429,CVE-2026-7168,CVE-2026-6253,CVE-2026-6276,CVE-2026-7009,CVE-2026-5773.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 21, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#May_21_2026</id>
    <updated>2026-05-21T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_21_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-129-19506-120-97_">cos-129-19506-120-97 <a id='"cos-arm64-129-19506-120-97"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/dfd76308ba62f00253b0f99cf10089931d12241d
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.97/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<h3 id="cos-dev-133-19804-0-0_">cos-dev-133-19804-0-0 <a id='"cos-arm64-dev-133-19804-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/39aff0f4a2a2fe29718f45dcab025a25fc7c46d6
">COS-6.18.32</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19804.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Switch cchost-* boards to legacy iptables.</p>
<h3>Change</h3>
<p>Added support for the R595 Nvidia driver production branch.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v535.309.01.</p>
<h3>Change</h3>
<p>Apply hardening sysctls on cchost boards.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.03.</p>
<h3>Change</h3>
<p>Dropped support for the NVIDIA 535 drivers.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v595.71.05.</p>
<h3>Change</h3>
<p>Enabled mm hardening kernel cmdlines on cchost.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Change</h3>
<p>Increased the size of the EFI partition from 32 MiB to 64 MiB and increased the sizes of both kernel partitions from 16 MiB to 32 MiB on x86.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.1.</p>
<h3>Change</h3>
<p>Made it so that /etc/machine-id is mounted with noexec, nosuid, and nodev.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.2.</p>
<h3>Change</h3>
<p>Switch cchost-* boards to legacy iptables.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38584 in the Linux kernel.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.18.32.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23473 in the Linux kernel.</p>
<h3>Change</h3>
<p>Updated uhaul to v6.18-0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43060 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgrade the Linux kernel to version 6.18.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43063 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded sys-apps/xemu to v0.0.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43065 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded sys-fs/cryptsetup to v2.8.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43066 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded sysram to v6.18-0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43067 in the Linux kernel.</p>
<h3>Feature</h3>
<p>Added the cos_kernel_args tool that allows manipulating kernel command line arguments of a COS image.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43068 in the Linux kernel.</p>
<h3>Feature</h3>
<p>Added nvidia-fs support to the COS GPU installer.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43071 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43073 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43079 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.03.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43085 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v595.71.05.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43086 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA drivers v580.126.16 and v580.126.20.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43089 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Dropped support for NVIDIA MFT Tools v4.32.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43090 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded CASFS to v0.1.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43091 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/oslogin to v20260227.00.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43093 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/oslogin to v20260430.00.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43094 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43099 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43107 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43112 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43114 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/chromeos-common-script to v0.0.1-r672.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43117 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/debugd-client to v0.0.1-r2738.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43329 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2026.04.24.230834-r272.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43332 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2026.05.06.161957-r274.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43333 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/power_manager-client to v0.0.1-r2973.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43336 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/session_manager-client to v0.0.1-r2834.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43338 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43339 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.53.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43341 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.8.0.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43350 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.8.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43359 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libnetfilter_queue to v1.0.5-r1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43360 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43361 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43362 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libcap to v2.78.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43363 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43365 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded the dump capture kernel to Linux v6.18.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43366 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43374 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-34743 in app-arch/xz-utils.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43383 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35385 and CVE-2026-35386 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35414 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43393 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4046 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43394 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed EFI variable OOB read in grub config parsing.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43409 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed argument injection in toolbox.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43438 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated go to v1.25.9. This resolves CVE-2026-32280, CVE-2026-32281, CVE-2026-32283, CVE-2026-27140, CVE-2026-27144.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43439 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated the Linux kernel to v6.18.31.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43441 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded containerd to v2.2.3. This fixes CVE-2026-35469.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43448 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/openssl to v3.5.6 to fix CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31790.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43450 in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Added: dev.raid.sync_io_depth: 32</li>
<li>Added: fs.dentry-negative: 0</li>
<li>Added: fs.fanotify.watchdog_timeout: 0</li>
<li>Added: fs.fuse.default_request_timeout: 0</li>
<li>Added: fs.fuse.max_request_timeout: 0</li>
<li>Added: kernel.core_modes: socket</li>
<li>Added: kernel.hung_task_detect_count: 0</li>
<li>Added: kernel.panic_sys_info: </li>
<li>Added: net.ipv4.tcp_ecn_option: 2</li>
<li>Added: net.ipv4.tcp_ecn_option_beacon: 3</li>
<li>Added: net.ipv4.tcp_rto_max_ms: 120000</li>
<li>Added: net.ipv4.tcp_tw_reuse_delay: 1000</li>
<li>Added: net.ipv6.conf.all.force_forwarding: 0</li>
<li>Added: net.ipv6.conf.default.force_forwarding: 0</li>
<li>Added: net.ipv6.conf.docker0.force_forwarding: 0</li>
<li>Added: net.ipv6.conf.eth0.force_forwarding: 0</li>
<li>Added: net.ipv6.conf.lo.force_forwarding: 0</li>
<li>Added: vm.defrag_mode: 0</li>
<li>Added: vm.vfs_cache_pressure_denom: 100</li>
<li>Changed: fs.epoll.max_user_watches: 1808517 -&gt; 1808094</li>
<li>Changed: fs.fanotify.max_user_marks: 68412 -&gt; 68395</li>
<li>Changed: fs.inotify.max_user_watches: 64189 -&gt; 64173</li>
<li>Changed: kernel.threads-max: 63178 -&gt; 63459</li>
<li>Changed: net.core.rmem_max: 212992 -&gt; 4194304</li>
<li>Changed: net.core.wmem_max: 212992 -&gt; 4194304</li>
<li>Changed: net.ipv4.tcp_mem: 94017    125357  188034 -&gt; 93993 125327  187986</li>
<li>Changed: net.ipv4.tcp_rmem: 4096    131072  6291456 -&gt; 4096 131072  33554432</li>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 187989    250654  375978</li>
<li>Changed: net.ipv6.icmp.ratelimit: 1000 -&gt; 100</li>
<li>Changed: user.max_cgroup_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_fanotify_marks: 68412 -&gt; 68395</li>
<li>Changed: user.max_inotify_watches: 64189 -&gt; 64173</li>
<li>Changed: user.max_ipc_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_mnt_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_net_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_pid_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_time_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_user_namespaces: 31589 -&gt; 31729</li>
<li>Changed: user.max_uts_namespaces: 31589 -&gt; 31729</li>
<li>Deleted: fs.xfs.irix_sgid_inherit: 0</li>
<li>Deleted: fs.xfs.irix_symlink_mode: 0</li>
<li>Deleted: fs.xfs.speculative_cow_prealloc_lifetime: 300</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_loose: 1</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_closereq: 64</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_closing: 64</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_open: 43200</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_partopen: 480</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_request: 240</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_respond: 480</li>
<li>Deleted: net.netfilter.nf_conntrack_dccp_timeout_timewait: 240</li>
</ul></p>
<h3>Security</h3>
<p>Fixed CVE-2026-43451 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43470 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43472 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43475 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43482 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43486 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43487 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46333 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed argument injection in toolbox.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-132_">cos-121-18867-381-132 <a id='"cos-arm64-121-18867-381-132"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/068bbd7c450db6c0538186d272865f74efd74316
">COS-6.6.137</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.132/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This is an <a href="https://docs.cloud.google.com/container-optimized-os/docs/concepts/versioning#lts_refresh_releases">LTS Refresh release.</a></p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v535.309.01.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.03.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-configs to v20251014.00.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/docker-credential-helpers to v0.9.4.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.1.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libnetfilter_conntrack to v1.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libtirpc to v1.3.7.</p>
<h3>Fixed</h3>
<p>Upgraded net-nds/rpcbind to v1.2.8.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/acl to v2.3.2-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/gentoo-functions to v1.7.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-auth/pambase to v20251104.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libcap to v2.77.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0-r3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43187 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46333 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed argument injection in toolbox.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Added: net.ipv4.tcp_pingpong_thresh: 1</li>
</ul></p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-395-31_">cos-125-19216-395-31 <a id='"cos-arm64-125-19216-395-31"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/5241cda1d789949bbcddde5d9320a36c610237d4
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.31/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Switch cchost-* boards to legacy iptables.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v535.309.01.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.03.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v595.71.05.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.1.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38584 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23473 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46333 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed argument injection in toolbox.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-613-15_">cos-117-18613-613-15 <a id='"cos-arm64-117-18613-613-15"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3b26f2eb5b1d5bcf6947c6656262e5b073999775
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.15/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v535.309.01.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.159.03.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.4.</p>
<h3>Fixed</h3>
<p>Upgraded cos-gpu-installer to v2.7.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-46333 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed argument injection in toolbox.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 12, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#May_12_2026</id>
    <updated>2026-05-12T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_12_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-104_">cos-113-18244-582-104 <a id='"cos-arm64-113-18244-582-104"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/55acfaa0d8192e080417075465aaffd1f75df1a9
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.104/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 11, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#May_11_2026</id>
    <updated>2026-05-11T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_11_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-395-7_">cos-125-19216-395-7 <a id='"cos-arm64-125-19216-395-7"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8615dfb7470816ab28b148bb67bba5f12bb4ea0b
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.7/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250715  376068 -&gt; 188034    250714  376068</li>
</ul></p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-613-7_">cos-117-18613-613-7 <a id='"cos-arm64-117-18613-613-7"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e416822ebf1c6b3a9c3304ba8d9903b55190df6d
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.7/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>Addressed internal infrastructure issues. No substantial change.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 09, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#May_09_2026</id>
    <updated>2026-05-09T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_09_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-120-64_">cos-beta-129-19506-120-64 <a id='"cos-arm64-beta-129-19506-120-64"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/261ec2a82c20483a919d7d25c05c7138ed1859c8
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.64/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-43284 (dirtyfrag) in the Linux kernel.</p>
<h3>Change</h3>
<p>Apply hardening sysctls on cchost boards.</p>
<h3>Change</h3>
<p>Enabled mm hardening kernel cmdlines on cchost.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23255 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23302 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23458 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31614 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31694 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31700 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31708 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31716 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31733 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31738 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31752 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31774 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31781 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35385 and CVE-2026-35386 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43012 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43013 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43016 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43024 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43028 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43030 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43035 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43038 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43043 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43046 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43054 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43057 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded cos-gpu-installer to v2.6.8.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 08, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#May_08_2026</id>
    <updated>2026-05-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_08_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-395-4_">cos-125-19216-395-4 <a id='"cos-arm64-125-19216-395-4"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8615dfb7470816ab28b148bb67bba5f12bb4ea0b
">COS-6.12.85</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.395.4/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This is an <a href="https://docs.cloud.google.com/container-optimized-os/docs/concepts/versioning#lts_refresh_releases">LTS Refresh release.</a></p>
<h3>Security</h3>
<p>Fixed CVE-2026-43284 (dirtyfrag) in the Linux kernel.</p>
<h3>Change</h3>
<p>Apply hardening sysctls on cchost boards.</p>
<h3>Change</h3>
<p>Enabled mm hardening kernel cmdlines on cchost.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.51.2.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.7.4.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libnetfilter_conntrack to v1.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/procps to v4.0.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31693 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31694 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31700 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31708 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31716 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31738 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31752 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31774 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31781 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35385 and CVE-2026-35386 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43012 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43013 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43016 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43024 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43028 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43030 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43035 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43038 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43043 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43057 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded cos-gpu-installer to v2.6.8.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-125_">cos-121-18867-381-125 <a id='"cos-arm64-121-18867-381-125"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/cb29612e10c383e119032dbb62243c2284a7a18d
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.125/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-43284 (dirtyfrag) in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31693 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31694 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31700 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31708 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31738 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31752 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31781 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43013 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43016 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43024 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43028 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43030 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43035 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43038 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43043 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43054 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43057 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-613-5_">cos-117-18613-613-5 <a id='"cos-arm64-117-18613-613-5"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e416822ebf1c6b3a9c3304ba8d9903b55190df6d
">COS-6.6.137</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.613.5/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This is an <a href="https://docs.cloud.google.com/container-optimized-os/docs/concepts/versioning#lts_refresh_releases">LTS Refresh release.</a></p>
<h3>Security</h3>
<p>Fixed CVE-2026-43284 (dirtyfrag) in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded net-fs/cifs-utils to v7.5.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/talloc to v2.4.4.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libnetfilter_conntrack to v1.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libtirpc to v1.3.7-r2.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/acl to v2.3.2-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/procps to v4.0.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35385 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/libgcrypt to v1.10.4 to fix CVE-2026-41989.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Added: net.ipv4.tcp_pingpong_thresh: 1</li>
</ul></p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 07, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#May_07_2026</id>
    <updated>2026-05-07T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_07_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-103_">cos-113-18244-582-103 <a id='"cos-arm64-113-18244-582-103"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/55acfaa0d8192e080417075465aaffd1f75df1a9
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.103/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<!-- Aggregate release notes.
Please check whether the types are correct.
Available types are:
breaking_change|non_breaking_change|deprecation|feature|fix|security_bulletin|service_announcement|issue].
Please add another service_announcement block if this is an LTS Refresh release.-->
<h3>Security</h3>
<p>Fixed CVE-2026-23411 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31738 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31752 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43013 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43024 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43028 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43030 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43035 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43037 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43038 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43040 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43043 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43054 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-43057 in the Linux kernel.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-121_">cos-121-18867-381-121 <a id='"cos-arm64-121-18867-381-121"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/81a1a5c044b4f62bb492acb3dc787f12de339232
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.121/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-35385 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Upgraded cos-gpu-installer to v2.6.8.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 04, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#May_04_2026</id>
    <updated>2026-05-04T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_04_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-120-52_">cos-beta-129-19506-120-52 <a id='"cos-arm64-beta-129-19506-120-52"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ab5449e6af743561ec3d078ea8fcec22a07d8e75
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.52/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Added the cos_kernel_args tool that allows manipulating kernel command line arguments of a COS image.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.1.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-21709 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-39764 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-40135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68239 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23004 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23138 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23157 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23245 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23277 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23368 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23374 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23441 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23442 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31532 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31546 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31554 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31555 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31557 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31561 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31580 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31586 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31588 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31628 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31647 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31648 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31664 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31665 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31667 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31671 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31673 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31675 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31677 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31680 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31681 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31682 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/openssl to v3.5.6 to fix CVE-2026-28387,
CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31790.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-185_">cos-125-19216-220-185 <a id='"cos-arm64-125-19216-220-185"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6c4905f5e0a57864e8f8d2792397d30065f6ba4b
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.185/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2025-39764 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68239 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23004 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23138 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23157 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23277 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23375 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23391 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23401 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23417 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23439 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23458 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31546 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31554 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31555 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31561 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31590 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31593 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31614 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31628 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31647 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31665 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31671 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31673 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31675 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31677 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31680 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31681 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31682 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31688 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/openssl to v3.5.6 to fix CVE-2026-28387,
CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31790.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250715  376068 -&gt; 188034    250714  376068</li>
</ul></p>
<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-100_">cos-113-18244-582-100 <a id='"cos-arm64-113-18244-582-100"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/2e246cc16ea70388d1ce7be1ce694805ccb64d3f
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.100/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-37980 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23268 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23269 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23404 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23405 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23406 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23407 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23408 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23409 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23410 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31446 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31447 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31454 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31515 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31521 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31523 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31546 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31555 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31664 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31665 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31667 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31671 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31680 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31682 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-a9b8b18 in the Linux kernel.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-118_">cos-121-18867-381-118 <a id='"cos-arm64-121-18867-381-118"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/81a1a5c044b4f62bb492acb3dc787f12de339232
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.118/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.1.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22125 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23255 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23302 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23374 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23399 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23442 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31407 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31429 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31555 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31628 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31648 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31664 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31665 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31671 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31673 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31675 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31680 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31681 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31682 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31688 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded openssl to v3.0.20 to fix CVE-2026-28387,
CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31790.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-110_">cos-117-18613-534-110 <a id='"cos-arm64-117-18613-534-110"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3805daa9d669b5d7a32bf0655bc3bc8abb66eeb2
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.110/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22125 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23255 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23302 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23374 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23399 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31407 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31429 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31546 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31555 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31628 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31648 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31664 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31665 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31667 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31671 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31673 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31680 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31681 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31682 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31688 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded openssl to v3.0.20 to fix CVE-2026-28387,
CVE-2026-28388,CVE-2026-28389,CVE-2026-28390,CVE-2026-31790.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>May 01, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#May_01_2026</id>
    <updated>2026-05-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#May_01_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-120-44_">cos-beta-129-19506-120-44 <a id='"cos-arm64-beta-129-19506-120-44"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8656d3e850e89f3430c31b56ebae60096f99a71b
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.44/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the R595 Nvidia driver production branch.</p>
<h3>Change</h3>
<p>Made it so that /etc/machine-id is mounted with noexec, nosuid, and nodev.</p>
<h3>Feature</h3>
<p>Enabled CONFIG_SCHED_CLASS_EXT and CONFIG_EXT_GROUP_SCHED.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA drivers v580.126.16 and v580.126.20.</p>
<h3>Fixed</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Fixed an ext4/jbd2 performance regression on CPU Node.</p>
<h3>Fixed</h3>
<p>Optimized IOMMU reference counting using atomic64_inc_return().</p>
<h3>Fixed</h3>
<p>Serialized sequence allocation to prevent timeouts during
concurrent TLB invalidations.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23276 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23375 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23391 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23397 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23398 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23399 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23401 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23412 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23413 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23417 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23439 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23456 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23457 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23465 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23471 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31400 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31402 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31406 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31407 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31413 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31415 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31416 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31418 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31423 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31424 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31426 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31427 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31428 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31431 (copy.fail) in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31434 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31438 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31446 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31447 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31448 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31450 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31451 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31454 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31495 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31515 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31516 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31519 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31521 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31523 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31525 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31528 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31531 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32280, CVE-2026-32281, CVE-2026-32283,
CVE-2026-27140, CVE-2026-27144 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-34743 in app-arch/xz-utils.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4046 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250715  376068 -&gt; 188034    250714  376068</li>
</ul></p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-180_">cos-125-19216-220-180 <a id='"cos-arm64-125-19216-220-180"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/62c8397822908f2ff448fcb9691e81a9902dfc8b
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.180/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Made it so that /etc/machine-id is mounted with noexec, nosuid, and nodev.</p>
<h3>Fixed</h3>
<p>Fixed an ext4/jbd2 performance regression on CPU Node.</p>
<h3>Fixed</h3>
<p>Optimized IOMMU reference counting using atomic64_inc_return().</p>
<h3>Fixed</h3>
<p>Serialized sequence allocation to prevent timeouts during
concurrent TLB invalidations.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31431 (copy.fail) in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31664 in the Linux kernel.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-113_">cos-121-18867-381-113 <a id='"cos-arm64-121-18867-381-113"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/7241a904e8946d8c3871ed01783d66bcad649023
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.113/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Optimized IOMMU reference counting using atomic64_inc_return().</p>
<h3>Fixed</h3>
<p>Serialized sequence allocation to prevent timeouts during
concurrent TLB invalidations.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31431 (copy.fail) in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31454 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31546 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31667 in the Linux kernel.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-106_">cos-117-18613-534-106 <a id='"cos-arm64-117-18613-534-106"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/4b597462e86bbce53ec5e8a8e452751b7c8617c2
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.106/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Optimized IOMMU reference counting using atomic64_inc_return().</p>
<h3>Fixed</h3>
<p>Serialized sequence allocation to prevent timeouts during
concurrent TLB invalidations.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31431 (copy.fail) in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 28, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#April_28_2026</id>
    <updated>2026-04-28T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#April_28_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-174_">cos-125-19216-220-174 <a id='"cos-arm64-125-19216-220-174"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/86ce3b3fe7e3b54c836775f62acff9f5218e166e
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.174/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the R595 Nvidia driver production branch.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA drivers v580.126.16 and v580.126.20.</p>
<h3>Fixed</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.1.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/makedumpfile to v1.7.9.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22116 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-40135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-70873 in dev-db/sqlite.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23245 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23255 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23276 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23302 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23368 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23374 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23397 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23398 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23399 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23412 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23413 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23441 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23442 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23456 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23457 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23465 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23471 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31400 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31402 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31406 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31407 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31415 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31416 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31418 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31423 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31424 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31426 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31427 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31428 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31434 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31438 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31446 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31447 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31448 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31450 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31451 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31454 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31495 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31515 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31516 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31519 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31521 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31523 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31525 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31528 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31531 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31557 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31648 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31667 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32280, CVE-2026-32281, CVE-2026-32283,
CVE-2026-27140, CVE-2026-27144 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-34743 in app-arch/xz-utils.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4046 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-106_">cos-121-18867-381-106 <a id='"cos-arm64-121-18867-381-106"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/cce81d8ec032eaf4a27103743c3106ca5c4f14ec
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.106/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Added support for NVIDIA drivers v580.126.16 and v580.126.20.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-70873 in dev-db/sqlite.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31430 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31446 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31447 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31450 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31451 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31495 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31515 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31521 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31523 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31525 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32280, CVE-2026-32281, CVE-2026-32283,
CVE-2026-27140, CVE-2026-27144 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-34743 in app-arch/xz-utils.</p>
<h3>Security</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-104_">cos-117-18613-534-104 <a id='"cos-arm64-117-18613-534-104"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6d5420309dd6902776517e31546fbd26337d2819
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.104/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Added support for NVIDIA drivers v580.126.16 and v580.126.20.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-70873 in dev-db/sqlite.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31430 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31446 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31447 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31450 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31451 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31453 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31454 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31466 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31469 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31495 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31496 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31515 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31521 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31523 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31525 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32280, CVE-2026-32281, CVE-2026-32283,
CVE-2026-27140, CVE-2026-27144 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-34743 in app-arch/xz-utils.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 27, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#April_27_2026</id>
    <updated>2026-04-27T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#April_27_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-95_">cos-121-18867-381-95 <a id='"cos-arm64-121-18867-381-95"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e0aeb6772ffabffa654fb3039d17167686a5d4b6
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.8</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.95/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Resolved an issue that could cause soft lockups
in stressed environments when iommu.strict=1.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/node-problem-detector to v0.8.25.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.401.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Fixed</h3>
<p>Upgraded virtual/logger to v0-r3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31415 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31416 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31418 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31423 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31424 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31426 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31427 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31428 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35414 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4046 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-a9b8b18 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded containerd to v2.0.8. This fixes CVE-2026-35469.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-95_">cos-117-18613-534-95 <a id='"cos-arm64-117-18613-534-95"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/db065d1e581611d7f1ef1451eb2d54ed3e1e43bc
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.95/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Resolved an issue that could cause soft lockups
in stressed environments when iommu.strict=1</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/node-problem-detector to v0.8.25.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31415 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31416 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31418 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31423 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31424 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31426 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31427 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31428 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35414 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4046 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-42156f9 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-a9b8b18 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated spdystream to v0.5.1 for containerd. This fixed CVE-2026-35469.</p>
<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-86_">cos-113-18244-582-86 <a id='"cos-arm64-113-18244-582-86"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/5b7904f18e1dfecfd30cf5076f57f302029b6404
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.86/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23360 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23401 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31415 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31416 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31418 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31423 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31424 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31427 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31428 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated spdystream to v0.5.1 for containerd. This fixed CVE-2026-35469.</p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-150_">cos-125-19216-220-150 <a id='"cos-arm64-125-19216-220-150"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/290dd196f19720702d0837eb8c03202d0f63b7ef
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.150/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Resolved an issue that could cause soft lockups
in stressed environments when iommu.strict=1</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.2.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/libseccomp to v2.6.0-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35414 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-7e3955b in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-a9b8b18 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded containerd to v2.1.7. This fixes CVE-2026-35469.</p>
<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-120-15_">cos-beta-129-19506-120-15 <a id='"cos-arm64-beta-129-19506-120-15"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/494b0342b38b614242985fa139fc510253b3b81f
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.3</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.120.15/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-admin/fluent-bit to v4.2.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/pv to v1.10.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/lsof to v4.99.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0994 in dev-libs/protobuf.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-35414 in net-misc/openssh.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-4437,CVE-2026-4438 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed KCTF-7e3955b in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-a9b8b18 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgrdaed containerd to v2.2.3. This fixes CVE-2026-35469.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 13, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#April_13_2026</id>
    <updated>2026-04-13T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#April_13_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-0-140_">cos-beta-129-19506-0-140 <a id='"cos-arm64-beta-129-19506-0-140"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3dee22804a41a202d6d8646c9504236d05170730
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.0.140/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<h3 id="cos-dev-133-19700-0-0_">cos-dev-133-19700-0-0 <a id='"cos-arm64-dev-133-19700-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e1d779f9a514b8e89a4661da858601d143841c0c
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.1</td>
<td><a href="https://storage.googleapis.com/cos-tools/19700.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Announcement</h3>
<p>This is an <a href="https://docs.cloud.google.com/container-optimized-os/docs/concepts/versioning#lts_refresh_releases">LTS Refresh release.</a></p>
<h3>Change</h3>
<p>Added support for 8th generation TPU devices.</p>
<h3>Change</h3>
<p>Fixed CVE-2026-33997 and CVE-2026-34040 in Docker.</p>
<h3>Feature</h3>
<p>Changed default sysctl networking values on A4x-max machine type only.</p>
<h3>Change</h3>
<p>Upgraded sys-apps/iproute2 to version 6.18.0.</p>
<h3>Feature</h3>
<p>Reverted iproute2 to v5.16.0.</p>
<h3>Feature</h3>
<p>Changed default sysctl networking values on A4x-max machine type only.</p>
<h3>Fixed</h3>
<p>Upgraded app-arch/unzip to v6.0_p29-r2.</p>
<h3>Feature</h3>
<p>Reverted iproute2 to v5.16.0.</p>
<h3>Fixed</h3>
<p>Upgraded app-containers/cni-plugins to v1.9.1.</p>
<h3>Fixed</h3>
<p>Fixed a kernel panic in virtio_pci teardown when virtual queues are conditionally skipped.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.2.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.1-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.401.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/pv to v1.10.4.</p>
<h3>Fixed</h3>
<p>Upgraded sys-libs/zlib to v1.3.2-r1.</p>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.2.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250715  376068 -&gt; 188034    250714  376068</li>
</ul></p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.51.2.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.1-r3.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.401.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/procps to v4.0.6.</p>
<h3>Fixed</h3>
<p>Upgraded virtual/logger to v0-r3.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-14027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23270 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-7cb9a23 in the Linux kernel.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-81_">cos-121-18867-381-81 <a id='"cos-arm64-121-18867-381-81"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/71cd44c2ce14a7098a606eb6f627d68348342bae
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.81/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-14027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-43826 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38704 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-39748 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-39764 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23154 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23343 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23360 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23401 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23412 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23413 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23414 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23439 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23441 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23456 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23457 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23458 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23471 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31400 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31402 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-33997 and CVE-2026-34040 in Docker.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-80_">cos-117-18613-534-80 <a id='"cos-arm64-117-18613-534-80"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/fd4744a57de7a7334d4bade6ccb2ae20d0a0fdf3
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.80/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.2.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.401.</p>
<h3>Fixed</h3>
<p>Upgraded virtual/logger to v0-r3.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-14027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23154 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23244 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23319 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23343 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23360 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23401 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23439 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23441 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23456 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23457 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23458 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23471 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31400 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31402 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-33997 and CVE-2026-34040 in Docker.</p>
<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-80_">cos-113-18244-582-80 <a id='"cos-arm64-113-18244-582-80"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/c6ca9a3a76c52435cb9459a6c724d8e25cc02e22
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.80/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-shells/dash to v0.5.13.2.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.401.</p>
<h3>Fixed</h3>
<p>Upgraded virtual/logger to v0-r3.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38162 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-39764 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23154 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23343 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23439 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23449 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23452 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23455 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23456 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23457 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23458 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31400 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31402 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-31403 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-33997 and CVE-2026-34040 in Docker.</p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-130_">cos-125-19216-220-130 <a id='"cos-arm64-125-19216-220-130"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ac718bd9b1307ca355c5ad6cfcd520cdd7f6e27d
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.130/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Changed default sysctl networking values on A4x-max machine type only.</p>
<h3>Feature</h3>
<p>Reverted iproute2 to v5.16.0.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.1-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/hwdata to v0.401.</p>
<h3>Fixed</h3>
<p>Upgraded virtual/logger to v0-r3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23343 in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 06, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#April_06_2026</id>
    <updated>2026-04-06T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#April_06_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-62_">cos-117-18613-534-62 <a id='"cos-arm64-117-18613-534-62"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/adc0dc9357977720199f700bbea8912f61c934a9
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.62/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2024-43826 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38704 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-39748 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-39764 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-40135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68206 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68239 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23004 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23138 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23245 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23270 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23271 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23277 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23340 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23397 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23398 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23412 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23413 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23414 in the Linux kernel.</p>
<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-62_">cos-113-18244-582-62 <a id='"cos-arm64-113-18244-582-62"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/bd30b98f1ad2d619c26425f9698025613037e170
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.62/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2025-38192 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-40135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68206 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68239 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68265 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23100 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23113 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23245 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23270 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23271 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23277 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23381 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23397 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23398 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-9df9578 in the Linux kernel.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-63_">cos-121-18867-381-63 <a id='"cos-arm64-121-18867-381-63"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/881eed6735256ed08c042b5ae37423670343957b
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.63/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2025-40135 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68206 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68239 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23004 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23050 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23138 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23245 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23270 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23271 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23277 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23388 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23391 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23397 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23398 in the Linux kernel.</p>
<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-0-121_">cos-beta-129-19506-0-121 <a id='"cos-arm64-beta-129-19506-0-121"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/3c72f15648aedcf11689537f9545addd4377da5f
">COS-6.12.67</a></td>
<td>v27.5.1</td>
<td>v2.2.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.0.121/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<h3 id="cos-dev-133-19681-0-0_">cos-dev-133-19681-0-0 <a id='"cos-arm64-dev-133-19681-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/350c271d1b528bc4fe572d2cadd2a16c3a758e41
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.1</td>
<td><a href="https://storage.googleapis.com/cos-tools/19681.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Upgraded sys-apps/iproute2 to version 6.18.0.</p>
<h3>Change</h3>
<p>Fixes a kernel panic in virtio_pci teardown when virtually queues are conditionally skipped.</p>
<h3>Fixed</h3>
<p>Fixed a kernel panic in virtio_pci teardown when virtually queues are conditionally skipped.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-33997 and CVE-2026-34040 in Docker.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-14027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-7cb9a23 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23270 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded sys-apps/iproute2 to version 6.18.0.</p>
<h3>Security</h3>
<p>Fixed KCTF-7cb9a23 in the Linux kernel.</p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-117_">cos-125-19216-220-117 <a id='"cos-arm64-125-19216-220-117"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/f66bf9eb15aea83cae027143806b6af01481c296
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.117/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Made it so that /dev/hugepages is mounted as noexec for cchost boards.</p>
<h3>Change</h3>
<p>Made it so that /mnt/disks is mounted as noexec for cchost boards.</p>
<h3>Change</h3>
<p>Made it so that /run is mounted as noexec for cchost boards.</p>
<h3>Change</h3>
<p>Upgraded sys-apps/iproute2 to version 6.18.0.</p>
<h3>Fixed</h3>
<p>Fixed a kernel panic in virtio_pci teardown when virtually queues are conditionally skipped.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-14027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23270 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23304 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-33997 and CVE-2026-34040 in Docker.</p>
<h3>Security</h3>
<p>Fixed KCTF-7cb9a23 in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>April 01, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#April_01_2026</id>
    <updated>2026-04-01T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#April_01_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-0-115_">cos-beta-129-19506-0-115 <a id='"cos-arm64-beta-129-19506-0-115"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/808b921cc891c1cb66519d4374662823bfe1713a
">COS-6.12.67</a></td>
<td>v27.5.1</td>
<td>v2.2.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.0.115/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<h3 id="cos-dev-133-19672-0-0_">cos-dev-133-19672-0-0 <a id='"cos-arm64-dev-133-19672-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/95e3317c03816d2a958f9aee05d52d08c50b7e2c
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.1</td>
<td><a href="https://storage.googleapis.com/cos-tools/19672.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2024-14027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-7cb9a23 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-7cb9a23 in the Linux kernel.</p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-106_">cos-125-19216-220-106 <a id='"cos-arm64-125-19216-220-106"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ff3a3595bc985d25661d470eab88dd46aa459d98
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.106/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2024-14027 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23304 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-7cb9a23 in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 30, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_30_2026</id>
    <updated>2026-03-30T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_30_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-0-109_">cos-beta-129-19506-0-109 <a id='"cos-arm64-beta-129-19506-0-109"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/82c29e7c6b260a76fdf55a67f4339c2bcb44b824
">COS-6.12.67</a></td>
<td>v27.5.1</td>
<td>v2.2.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.0.109/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<h3 id="cos-dev-133-19666-0-0_">cos-dev-133-19666-0-0 <a id='"cos-arm64-dev-133-19666-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ef4e393c358e8c7675d8c2a260cbca1163ead2a3
">COS-6.12.77</a></td>
<td>v27.5.1</td>
<td>v2.2.1</td>
<td><a href="https://storage.googleapis.com/cos-tools/19666.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Fixed CVE-2026-27135 in net-libs/nghttp2.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.77.</p>
<h3>Feature</h3>
<p>Enabled dynamic configuration of FUSE max pages limit.</p>
<h3>Feature</h3>
<p>Enabled dynamic configuration of FUSE max pages limit.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23292 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27135 in net-libs/nghttp2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23293 in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Added: fs.fuse.max_pages_limit: 256</li>
</ul></p>
<h3>Security</h3>
<p>Fixed CVE-2026-23296 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23297 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23300 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23304 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23310 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23316 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23319 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23340 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23352 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23359 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23360 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23380 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23381 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23383 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23388 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23390 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-9df9578 in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Added: fs.fuse.max_pages_limit: 256</li>
</ul></p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-99_">cos-125-19216-220-99 <a id='"cos-arm64-125-19216-220-99"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/bcbb125a5a57da7523992b266b4f07d3510bd0de
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.99/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Enabled dynamic configuration of FUSE max pages limit.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23292 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23293 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23296 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23297 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23300 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23310 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23316 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23319 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23340 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23352 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23359 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23360 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23380 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23381 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23383 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23388 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23390 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27135 in net-libs/nghttp2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27448 in dev-python/pyopenssl.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27459 in dev-python/pyopenssl.</p>
<h3>Security</h3>
<p>Fixed KCTF-9df9578 in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Added: fs.fuse.max_pages_limit: 256</li>
</ul></p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-56_">cos-121-18867-381-56 <a id='"cos-arm64-121-18867-381-56"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/31a85cce1fd063629a36c894be803b515077311b
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.56/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Feature</h3>
<p>Added support for loading the ublk kernel module.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23292 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23293 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23296 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23300 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23304 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23310 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23340 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23352 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23359 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23368 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23381 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23386 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27135 in net-libs/nghttp2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27448 in dev-python/pyopenssl.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27459 in dev-python/pyopenssl.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32597 with pyjwt package upgrade to 2.12.1.</p>
<h3>Security</h3>
<p>Fixed KCTF-329f0b9 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-9df9578 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed the "CrackArmor" vulnerability in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: kernel.threads-max: 63487 -&gt; 63199</li>
<li>Changed: user.max_cgroup_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_ipc_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_mnt_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_net_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_pid_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_time_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_user_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_uts_namespaces: 31743 -&gt; 31599</li>
</ul></p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-53_">cos-117-18613-534-53 <a id='"cos-arm64-117-18613-534-53"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/0af9e0905663e609aafa3b8d9c485e534efdd2a9
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.53/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-23292 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23293 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23296 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23300 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23304 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23310 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23351 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23352 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23359 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23368 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23381 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23386 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23388 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23391 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27135 in net-libs/nghttp2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27448 in dev-python/pyopenssl.</p>
<h3>Security</h3>
<p>Fixed the "CrackArmor" vulnerability in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed the "CrackArmor" vulnerability in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: kernel.threads-max: 63487 -&gt; 63199</li>
<li>Changed: user.max_cgroup_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_ipc_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_mnt_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_net_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_pid_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_time_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_user_namespaces: 31743 -&gt; 31599</li>
<li>Changed: user.max_uts_namespaces: 31743 -&gt; 31599</li>
</ul></p>
<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-55_">cos-113-18244-582-55 <a id='"cos-arm64-113-18244-582-55"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/a5e67a9c58dc766e562460c826eac46e42da4ada
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.55/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Updated cos-gpu-installer to v2.6.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23292 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23293 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23296 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23300 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23303 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23304 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23340 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23352 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23359 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23368 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23388 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23391 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23392 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27135 in net-libs/nghttp2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27448 in dev-python/pyopenssl.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27459 in dev-python/pyopenssl.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32597 with pyjwt package upgrade to 2.12.1.</p>
<h3>Security</h3>
<p>Fixed KCTF-329f0b9 in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: kernel.threads-max: 63503 -&gt; 63215</li>
<li>Changed: user.max_cgroup_namespaces: 31751 -&gt; 31607</li>
<li>Changed: user.max_ipc_namespaces: 31751 -&gt; 31607</li>
<li>Changed: user.max_mnt_namespaces: 31751 -&gt; 31607</li>
<li>Changed: user.max_net_namespaces: 31751 -&gt; 31607</li>
<li>Changed: user.max_pid_namespaces: 31751 -&gt; 31607</li>
<li>Changed: user.max_time_namespaces: 31751 -&gt; 31607</li>
<li>Changed: user.max_user_namespaces: 31751 -&gt; 31607</li>
<li>Changed: user.max_uts_namespaces: 31751 -&gt; 31607</li>
</ul></p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 26, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_26_2026</id>
    <updated>2026-03-26T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_26_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-0-98_">cos-beta-129-19506-0-98 <a id='"cos-arm64-beta-129-19506-0-98"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/665d2061d21ae56123f4de285c75962c6cf56b91
">COS-6.12.67</a></td>
<td>v27.5.1</td>
<td>v2.2.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.0.98/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p249 drivers.</p>
<h3>Change</h3>
<p>Fixed CVE-2026-32597 with pyjwt package upgrade to 2.12.1.</p>
<h3>Feature</h3>
<p>Added support for loading the ublk kernel module.</p>
<h3>Fixed</h3>
<p>Fixed an ek-cpu-balloon bug which would result in CPUs being underreported on ek machines with SMT enabled.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-osconfig-agent to v20260119.00.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71265 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71266 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71267 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71268 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23069 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23083 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23085 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23095 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23097 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23099 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23103 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23105 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23110 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23254 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23262 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-329f0b9 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-c9bc175 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-libs/openssl to v3.5.5. This resolves CVE-2025-15467.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.19.0. This resolves CVE-2026-1965 and CVE-2026-3783.</p>
<h3>Security</h3>
<p>Updated sys-libs/binutils-libs to 2.46.0. This resolves CVE-2025-69644.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-48_">cos-117-18613-534-48 <a id='"cos-arm64-117-18613-534-48"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/b30c5b2734870c7802c8a3e6691ff29d8e65b739
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.48/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p249 drivers.</p>
<h3>Feature</h3>
<p>Added support for loading the ublk kernel module.</p>
<h3>Fixed</h3>
<p>Updated cos-gpu-installer to v2.6.1.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-osconfig-agent to v20260119.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47-r1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23231 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23254 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-27459 in dev-python/pyopenssl.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32597 with pyjwt package upgrade to 2.12.1.</p>
<h3>Security</h3>
<p>Fixed KCTF-329f0b9 in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 25, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_25_2026</id>
    <updated>2026-03-25T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_25_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-87_">cos-125-19216-220-87 <a id='"cos-arm64-125-19216-220-87"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/98c1b6ad6f970918e8fe029d2ee331c556111ae3
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.87/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p249 drivers.</p>
<h3>Feature</h3>
<p>Added support for loading the ublk kernel module.</p>
<h3>Fixed</h3>
<p>Added CPU balloon support for Arm CPUs.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-osconfig-agent to v20260119.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47-r1.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71265 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71266 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71267 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71268 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23254 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23262 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32597 with pyjwt package upgrade to 2.12.1.</p>
<h3>Security</h3>
<p>Fixed KCTF-329f0b9 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-c9bc175 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.19.0. This resolves CVE-2026-1965 and CVE-2026-3783.</p>
<h3>Security</h3>
<p>Updated sys-libs/binutils-libs to 2.46.0. This resolves CVE-2025-69644.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-dev-133-19654-0-0_">cos-dev-133-19654-0-0 <a id='"cos-arm64-dev-133-19654-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8ecb3fb8b4bed2db662e41f5991ae84debec7939
">COS-6.12.76</a></td>
<td>v27.5.1</td>
<td>v2.2.1</td>
<td><a href="https://storage.googleapis.com/cos-tools/19654.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Fixed an ek-cpu-balloon bug which would result in CPUs being underreported on ek machines with SMT enabled.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.51.3.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.7.5.</p>
<h3>Fixed</h3>
<p>Upgraded virtual/logger to v0-r3.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-32597 with pyjwt package upgrade to v2.12.1.</p>
<h3>Security</h3>
<p>Fixed KCTF-329f0b9 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-c9bc175 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.19.0. This resolves CVE-2026-1965 and CVE-2026-3783.</p>
<h3>Security</h3>
<p>Updated sys-libs/binutils-libs to 2.46.0. This resolves CVE-2025-69644.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 23, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_23_2026</id>
    <updated>2026-03-23T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_23_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-72_">cos-125-19216-220-72 <a id='"cos-arm64-125-19216-220-72"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/6df21e3fc3957bf2dc7eeb7d8e703fc57b1e07ac
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.72/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p249 drivers.</p>
<h3>Fixed</h3>
<p>Added CPU balloon support for Arm CPUs.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-osconfig-agent to v20260119.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47-r1.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71265 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71266 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71267 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71268 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23254 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23262 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.19.0. This resolves CVE-2026-1965 and CVE-2026-3783.</p>
<h3>Security</h3>
<p>Updated sys-libs/binutils-libs to 2.46.0. This resolves CVE-2025-69644.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-45_">cos-121-18867-381-45 <a id='"cos-arm64-121-18867-381-45"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/d8086709417b04f7a79c84710f6bf3db42e87814
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.45/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p249 drivers.</p>
<h3>Fixed</h3>
<p>Updated cos-gpu-installer to v2.6.1.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-osconfig-agent to v20260119.00.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47-r1.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-69647 in binutils-libs.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-69648 in binutils-libs.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23254 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-71e99ee in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.19.0. This resolves CVE-2026-1965 and CVE-2026-3783.</p>
<h3>Security</h3>
<p>Updated sys-libs/binutils-libs to 2.46.0. This resolves CVE-2025-69644.</p>
<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-dev-133-19633-0-0_">cos-dev-133-19633-0-0 <a id='"cos-arm64-dev-133-19633-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/788077df45931035984615c9958e274d89bd7e1f
">COS-6.12.76</a></td>
<td>v27.5.1</td>
<td>v2.2.1</td>
<td><a href="https://storage.googleapis.com/cos-tools/19633.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p249 drivers.</p>
<h3>Feature</h3>
<p>Added support for 8th generation TPU devices.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-osconfig-agent to v20260119.00.</p>
<h3>Fixed</h3>
<p>Upgraded chromeos-base/google-breakpad to v2026.03.03.162944-r270.</p>
<h3>Fixed</h3>
<p>Upgraded dev-libs/expat to v2.7.4.</p>
<h3>Fixed</h3>
<p>Upgraded net-firewall/iptables to v1.8.13.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47-r1.</p>
<h3>Security</h3>
<p>Fixed KCTF-c9bc175 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.19.0. This resolves CVE-2026-1965 and CVE-2026-3783.</p>
<h3>Security</h3>
<p>Updated sys-libs/binutils-libs to 2.46.0. This resolves CVE-2025-69644.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-44_">cos-117-18613-534-44 <a id='"cos-arm64-117-18613-534-44"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e91b457d7df4624c595f612f65f6a2f2bc973df4
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.44/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p249 drivers.</p>
<h3>Fixed</h3>
<p>Updated cos-gpu-installer to v2.6.1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47-r1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23231 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23254 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.19.0. This resolves CVE-2026-1965 and CVE-2026-3783.</p>
<h3>Security</h3>
<p>Updated sys-libs/binutils-libs to 2.46.0. This resolves CVE-2025-69644.</p>
<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-47_">cos-113-18244-582-47 <a id='"cos-arm64-113-18244-582-47"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/824daafa5f157963eea76b8fc10de1d2df43be70
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.47/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47-r1.</p>
<h3>Security</h3>
<p>Fixed CVE-2024-26822 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-69647 in binutils-libs.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23243 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated net-misc/curl to v8.19.0. This resolves CVE-2026-1965 and CVE-2026-3783.</p>
<h3>Security</h3>
<p>Updated sys-libs/binutils-libs to 2.46.0. This resolves CVE-2025-69644.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 17, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_17_2026</id>
    <updated>2026-03-17T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_17_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-0-66_">cos-beta-129-19506-0-66 <a id='"cos-arm64-beta-129-19506-0-66"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/e2ad9be2a74b62aaf49320d42f7a9ca47132ad5e
">COS-6.12.67</a></td>
<td>v27.5.1</td>
<td>v2.2.2</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.0.66/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<h3 id="cos-dev-133-19619-0-0_">cos-dev-133-19619-0-0 <a id='"cos-arm64-dev-133-19619-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8f01bd7cad431636ba9b859cd3fb0f169e55a58c
">COS-6.12.76</a></td>
<td>v27.5.1</td>
<td>v2.2.1</td>
<td><a href="https://storage.googleapis.com/cos-tools/19619.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p246 drivers.</p>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p246 drivers.</p>
<h3>Change</h3>
<p>Fixed the "CrackArmor" vulnerability in the Linux kernel.</p>
<h3>Change</h3>
<p>Fixed the "CrackArmor" vulnerability in the Linux kernel.</p>
<h3>Breaking</h3>
<p><code>/dev/hugepages</code> is now mounted with the <code>noexec</code> option.</p>
<h3>Breaking</h3>
<p><code>/dev/hugepages</code> is now mounted with the <code>noexec</code> option.</p>
<h3>Change</h3>
<p>Updated cos-gpu-installer to v2.6.0.</p>
<h3>Breaking</h3>
<p><code>/run</code> is now mounted with the <code>noexec</code> option.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.76.</p>
<h3>Change</h3>
<p>Updated cos-gpu-installer to v2.6.0.</p>
<h3>Change</h3>
<p>Upgraded CASFS to v0.1.2.</p>
<h3>Change</h3>
<p>Upgraded CASFS to v0.1.2.</p>
<h3>Feature</h3>
<p>Switched to using systemd-resolved stub resolver by default, which fixes DNS caching issues.</p>
<h3>Change</h3>
<p>Upgraded app-containers/containerd to v2.2.2.</p>
<h3>Feature</h3>
<p>Added support for larger ring sizes for the GVNIC driver in DQO-QPL mode.</p>
<h3>Change</h3>
<p>Upgraded dev-libs/glib to v2.86.3. This fixes CVE-2025-14087, CVE-2025-14512 and CVE-2025-13601.</p>
<h3>Feature</h3>
<p>Added support for larger ring sizes for the GVNIC driver in DQO-QPL mode.</p>
<h3>Fixed</h3>
<p>Fixed a kernel bug which could cause traffic drops after NIC resets.</p>
<h3>Fixed</h3>
<p>Updated cos-gpu-installer to v2.6.1.</p>
<h3>Fixed</h3>
<p>Enabled buffer overflow detection for kernel str/mem functions.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.0.</p>
<h3>Fixed</h3>
<p>Fixed a kernel bug which could cause traffic drops after NIC resets.</p>
<h3>Fixed</h3>
<p>Upgraded dev-util/gn to v2331.</p>
<h3>Fixed</h3>
<p>Fixed performance and efficiency issues in TCPX through optimized netmem handling and scatter-gather list coalescing for large memory mappings.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/acl to v2.3.2-r3.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47.</p>
<h3>Fixed</h3>
<p>Updated cos-gpu-installer to v2.6.1.</p>
<h3>Fixed</h3>
<p>Upgraded the galog version to v0.0.0-20250924170816-9dbf105986f4 in google-guest-agent to fix an issue with high CPU consumption.</p>
<h3>Fixed</h3>
<p>Upgraded dev-utils/gdbus-codegen to v2.86.3.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/glib to v2.86.3. This fixes CVE-2025-14087, CVE-2025-14512 and CVE-2025-13601.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/fluent-bit to v4.2.3.1.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.0.</p>
<h3>Fixed</h3>
<p>Upgraded dev-util/gdbus-codegen to v2.86.3.</p>
<h3>Fixed</h3>
<p>Upgraded the galog version to v0.0.0-20250924170816-9dbf105986f4 in google-guest-agent to fix an issue with high CPU consumption.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23229 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23230 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23240 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed a packet header clobbering issue in the IDPF driver occurring when SWIOTLB and header split are enabled.</p>
<h3>Security</h3>
<p>Fixed KCTF-71e99ee in the Linux kernel.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-35_">cos-121-18867-381-35 <a id='"cos-arm64-121-18867-381-35"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/c11b19e08b7dec3a166539d526b69fca5d0056e1
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.35/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2025-38162 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38201 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23102 in the Linux kernel.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-36_">cos-117-18613-534-36 <a id='"cos-arm64-117-18613-534-36"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/530d6a57e6fea7de26a9600dd43f981ade00d33e
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.36/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2025-38162 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38162 in the Linux kernel.</p>
<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-42_">cos-113-18244-582-42 <a id='"cos-arm64-113-18244-582-42"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/debd483161918f36c7d50ad90146fafe073f6a8f
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.42/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-23054 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-71e99ee in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 14, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_14_2026</id>
    <updated>2026-03-14T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_14_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-57_">cos-125-19216-220-57 <a id='"cos-arm64-125-19216-220-57"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/92c9f3ce0777cb6759e4c8a66adac2583c5ba3a8
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.57/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Fixed the "CrackArmor" vulnerability in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Downgraded ek-cpu-balloon driver to version 1.1.0 to address efficiency daemon issues.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 10, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_10_2026</id>
    <updated>2026-03-10T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_10_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-40_">cos-113-18244-582-40 <a id='"cos-arm64-113-18244-582-40"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/da5dc8347ba20698e2b8e3a27f2f4b5783e11c98
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.40/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47.</p>
<h3>Security</h3>
<p>Fixed CVE-2023-53421 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-13601, CVE-2025-14512, CVE-2025-14087 in
dev-libs/glib.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-37920 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38201 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38591 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-40251 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71089 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23216 in the Linux kernel.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-35_">cos-117-18613-534-35 <a id='"cos-arm64-117-18613-534-35"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/810772cc40b9bc07245d9d7059e7f2d697995adf
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.35/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-22026 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38201 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23100 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23216 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23229 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23230 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/glib to v2.86.3 and gdbus-codegen to v2.86.3. This fixes
CVE-2025-14087, CVE-2025-14512 and CVE-2025-13601.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-30_">cos-121-18867-381-30 <a id='"cos-arm64-121-18867-381-30"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/894f17dcc8a978b3bd6e85e3cfe41e97d55a87d8
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.30/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.0.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/file to v5.47.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38234 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23100 in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 08, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_08_2026</id>
    <updated>2026-03-08T00:00:00-07:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_08_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-43_">cos-125-19216-220-43 <a id='"cos-arm64-125-19216-220-43"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/7eb31713b3fb44138b65643ab9d3037e22d29e47
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.43/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Updated cos-gpu-installer to v2.6.0.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/node-problem-detector to v0.8.25.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250714  376068 -&gt; 188034    250715  376068</li>
</ul></p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 07, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_07_2026</id>
    <updated>2026-03-07T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_07_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-39_">cos-125-19216-220-39 <a id='"cos-arm64-125-19216-220-39"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/7eb31713b3fb44138b65643ab9d3037e22d29e47
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.39/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Fixed a kernel bug which could cause traffic drops after NIC resets.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250715  376068 -&gt; 188034    250714  376068</li>
</ul></p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 06, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_06_2026</id>
    <updated>2026-03-06T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_06_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-38_">cos-125-19216-220-38 <a id='"cos-arm64-125-19216-220-38"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/7eb31713b3fb44138b65643ab9d3037e22d29e47
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.38/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2026-23100 in the Linux kernel.</p>
<h3>Change</h3>
<p>Runtime sysctl changes:
<ul>
<li>Changed: net.ipv4.udp_mem: 188034   250715  376068 -&gt; 188034    250714  376068</li>
</ul></p>
]]>
    </content>
  </entry>

  <entry>
    <title>March 04, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#March_04_2026</id>
    <updated>2026-03-04T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#March_04_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-29_">cos-113-18244-582-29 <a id='"cos-arm64-113-18244-582-29"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/2f3d82e8d18f259f62bd81421e80cfb19aa2a822
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.29/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Fixed an issue where most platforms would use only half of the available GVNIC TX queues.</p>
<h3>Fixed</h3>
<p>Upgraded net-dns/c-ares to v1.31.0.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v692.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-58187 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-6075 in python.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-60753 in libarchive.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-61732 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23086 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23112 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23119 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23124 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23145 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23156 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23168 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23198 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23205 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23212 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23193 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-e3f000f in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded net-misc/curl to version 8.18.0. This fixes CVE-2025-10966, CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, and CVE-2025-15224.</p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-34_">cos-125-19216-220-34 <a id='"cos-arm64-125-19216-220-34"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8ae4fb3efb4e9b9c6276d3c9247c7a123a73fca6
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.34/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p246 drivers.</p>
<h3>Fixed</h3>
<p>Upgraded dev-util/gdbus-codegen to v2.86.3.</p>
<h3>Fixed</h3>
<p>Upgraded the galog version to v0.0.0-20250924170816-9dbf105986f4 in google-guest-agent to fix an issue with high CPU consumption.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23204 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23229 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23230 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/glib to v2.86.3. This fixes
CVE-2025-14087, CVE-2025-14512 and CVE-2025-13601.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-24_">cos-121-18867-381-24 <a id='"cos-arm64-121-18867-381-24"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/8182b8864d9e39f8ec1bd6d96a4e6b2380412f26
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.24/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Fixed an issue where most platforms would use only half of the available GVNIC TX queues.</p>
<h3>Fixed</h3>
<p>Upgraded dev-util/gdbus-codegen to v2.86.3.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-58187 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23216 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23229 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23230 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded dev-libs/glib to v2.86.3. This fixes
CVE-2025-14087, CVE-2025-14512 and CVE-2025-13601.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-24_">cos-117-18613-534-24 <a id='"cos-arm64-117-18613-534-24"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/c6a9ce222e73689842f21f4e17890d16e03cd17b
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.24/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p246 drivers.</p>
<h3>Change</h3>
<p>Fixed an issue where most platforms would use only half of the available GVNIC TX queues.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-58187 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-61732 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed KCTF-e3f000f in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>February 27, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#February_27_2026</id>
    <updated>2026-02-27T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#February_27_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-14_">cos-121-18867-381-14 <a id='"cos-arm64-121-18867-381-14"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/c68efb7356143c761a7b8f1e048e0236ecb23d94
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.14/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Added support for the Lustre 2.14.0_p246 drivers.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-60753 in libarchive.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23112 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23179 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23193 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23198 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23200 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23204 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23205 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23212 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-e3f000f in the Linux kernel.</p>
]]>
    </content>
  </entry>

  <entry>
    <title>February 24, 2026</title>
    <id>tag:google.com,2016:cos-release-notes#February_24_2026</id>
    <updated>2026-02-24T00:00:00-08:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes#February_24_2026"/>
    <content type="html"><![CDATA[<strong class="release-note-product-version-title">Main</strong>
<h3>Change</h3>
<h3 id="cos-beta-129-19506-0-32_">cos-beta-129-19506-0-32 <a id='"cos-arm64-beta-129-19506-0-32"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/db611b456979827c0f71190bd2fd9868cec57510
">COS-6.12.67</a></td>
<td>v27.5.1</td>
<td>v2.2.0</td>
<td><a href="https://storage.googleapis.com/cos-tools/19506.0.32/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<h3 id="cos-dev-133-19566-0-0_">cos-dev-133-19566-0-0 <a id='"cos-arm64-dev-133-19566-0-0"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/ec8a48be0774f726990a93e2afead08ee16b3f2c
">COS-6.12.74</a></td>
<td>v27.5.1</td>
<td>v2.2.1</td>
<td><a href="https://storage.googleapis.com/cos-tools/19566.0.0/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Upgraded net-misc/curl to version 8.18.0. This fixes CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, and CVE-2025-15224.</p>
<h3>Feature</h3>
<p>Added support for  590.44.01 and 590.48.01 NVIDIA driver for NVIDIA_RTX_PRO_6000</p>
<h3>Change</h3>
<p>Made it so that /run is mounted as noexec.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.126.09-grid for NVIDIA_RTX_PRO_6000 GPU type.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-15281 and CVE-2026-0861 in sys-libs/glibc.</p>
<h3>Change</h3>
<p>Updated the Linux kernel to v6.12.74.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68358 in the Linux kernel.</p>
<h3>Change</h3>
<p>Upgraded containerd to v2.2.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68365 in the Linux kernel.</p>
<h3>Feature</h3>
<p>Added support for 590.44.01 and 590.48.01 NVIDIA driver for NVIDIA_RTX_PRO_6000</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68725 in the Linux kernel.</p>
<h3>Feature</h3>
<p>Added support for NVIDIA driver v535.288.01, v570.211.01 and v580.126.09.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71225 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23112 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.126.09-grid for NVIDIA_RTX_PRO_6000 GPU type.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23113 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Enabled buffer overflow detection for kernel str/mem functions.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23119 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/google-guest-agent to v20260121.00.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23124 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/oslogin to v20260128.00.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23148 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/oslogin to v20260129.00.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23154 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded dev-db/sqlite to v3.51.2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23156 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded net-libs/libnetfilter_conntrack to v1.1.1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23159 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.1-r2.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23161 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.0-r1.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23168 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/gentoo-functions to v1.7.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23173 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v692.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23177 in the Linux kernel.</p>
<h3>Fixed</h3>
<p>Upgraded sys-process/procps to v4.0.6.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23179 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23193 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-15281 and CVE-2026-0861 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23198 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-40147 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23199 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-0915 in sys-apps/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23200 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-e3f000f in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23204 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-f8db647 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23205 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-libs/libxml2 to version 2.14.6. This resolves CVE-2025-6021.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23212 in the Linux kernel.</p>
<h3>Security</h3>
<p>Updated dev-libs/openssl to v3.5.5. This resolves CVE-2025-15467.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded net-misc/curl to version 8.18.0. This fixes CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, and CVE-2025-15224.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23215 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23216 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23219 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-e3f000f in the Linux kernel.</p>
<strong class="release-note-product-version-title">125</strong>
<h3>Change</h3>
<h3 id="cos-125-19216-220-24_">cos-125-19216-220-24 <a id='"cos-arm64-125-19216-220-24"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/53881952835848fbf440de93baf50cf22f1e4785
">COS-6.12.68</a></td>
<td>v27.5.1</td>
<td>v2.1.5</td>
<td><a href="https://storage.googleapis.com/cos-tools/19216.220.24/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Change</h3>
<p>Fixed CVE-2026-23177 in the Linux kernel.</p>
<h3>Feature</h3>
<p>Added support for  590.44.01 and 590.48.01 NVIDIA driver for NVIDIA_RTX_PRO_6000</p>
<h3>Fixed</h3>
<p>Added support for NVIDIA driver v580.126.09-grid for NVIDIA_RTX_PRO_6000 GPU type.</p>
<h3>Fixed</h3>
<p>Upgraded app-admin/sosreport to v4.11.0.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/rsync to v3.4.1-r2.</p>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v692.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-15281 and CVE-2026-0861 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-47912, CVE-2025-58185, CVE-2025-58187, CVE-2025-58188, CVE-2025-58189, CVE-2025-61723, CVE-2025-61724, CVE-2025-61726, and CVE-2025-61728 in dev-lang/go.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-60753 in libarchive.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-71225 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23112 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23148 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23154 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23156 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23159 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23161 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23168 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23173 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23179 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23193 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23198 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23199 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23200 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23205 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23212 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23214 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23215 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23216 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23219 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-e3f000f in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-f41c5d1 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded net-misc/curl to version 8.18.0. This fixes CVE-2025-10148, CVE-2025-10966, CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, and CVE-2025-15224.</p>
<strong class="release-note-product-version-title">113</strong>
<h3>Change</h3>
<h3 id="cos-113-18244-582-11_">cos-113-18244-582-11 <a id='"cos-arm64-113-18244-582-11"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/5c4d6d97af15aedf3768f1e1cef2cdb5a5735ccc
">COS-6.1.161</a></td>
<td>v24.0.9</td>
<td>v1.7.27</td>
<td><a href="https://storage.googleapis.com/cos-tools/18244.582.11/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Security</h3>
<p>Fixed CVE-2023-54285 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-15281 and CVE-2026-0861 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-38232 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-68725 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-22998 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-22999 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23001 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23003 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23005 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23010 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23011 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23025 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23038 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23069 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23085 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23095 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23097 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23099 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23102 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23103 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23105 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23107 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23110 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-f41c5d1 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-f8db647 in the Linux kernel.</p>
<strong class="release-note-product-version-title">117</strong>
<h3>Change</h3>
<h3 id="cos-117-18613-534-15_">cos-117-18613-534-15 <a id='"cos-arm64-117-18613-534-15"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/62eaa6fec6fa6b8cc2b4146e32ae7139de26e9a4
">COS-6.6.123</a></td>
<td>v24.0.9</td>
<td>v1.7.29</td>
<td><a href="https://storage.googleapis.com/cos-tools/18613.534.15/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.0-r1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v692.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-15281 and CVE-2026-0861 in sys-libs/glibc.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-6075 in python.</p>
<h3>Security</h3>
<p>Fixed CVE-2025-60753 in libarchive.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23112 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23176 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23179 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23193 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23198 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23200 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23204 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23205 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23209 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed KCTF-f41c5d1 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded net-misc/curl to version 8.18.0. This fixes CVE-2025-10148, CVE-2025-10966, CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, and CVE-2025-15224.</p>
<strong class="release-note-product-version-title">121</strong>
<h3>Change</h3>
<h3 id="cos-121-18867-381-1_">cos-121-18867-381-1 <a id='"cos-arm64-121-18867-381-1"/'></a></h3>
<table class="pkg">
<tr>
<td>Kernel</td>
<td>Docker</td>
<td>Containerd</td>
<td><a href="https://cloud.google.com/container-optimized-os/docs/how-to/run-gpus">GPU Drivers</a></td>
</tr>
<tr>
<td><a href="https://cos.googlesource.com/third_party/kernel/+/648b5918d64d7a9788baa271ec7cb32d9b73c857
">COS-6.6.122</a></td>
<td>v27.5.1</td>
<td>v2.0.7</td>
<td><a href="https://storage.googleapis.com/cos-tools/18867.381.1/lakitu/gpu_driver_versions.textproto">See List</a></td>
</tr>
</table>
<h3>Fixed</h3>
<p>Upgraded net-misc/socat to v1.8.1.0-r1.</p>
<h3>Fixed</h3>
<p>Upgraded sys-apps/less to v692.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23156 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23159 in the Linux kernel.</p>
<h3>Security</h3>
<p>Fixed CVE-2026-23168 in the Linux kernel.</p>
<h3>Security</h3>
<p>Upgraded net-misc/curl to version 8.18.0. This fixes CVE-2025-10148, CVE-2025-10966, CVE-2025-13034, CVE-2025-14017, CVE-2025-14524, CVE-2025-14819, CVE-2025-15079, and CVE-2025-15224.</p>
]]>
    </content>
  </entry>

</feed>
