Container Optimized OS Update Addresses Numerous Linux Kernel and OpenSSH Vulnerabilities
securityinfragcppreviewsecurity-advisoryengineer
security patch
This Container Optimized OS (COS) update includes significant security enhancements, patching a vast number of CVEs in the Linux kernel and OpenSSH. It also applies hardening sysctls and kernel command lines on cchost boards, and upgrades the cos-gpu-installer and libgcrypt. These changes are critical for maintaining the security posture of containerized workloads running on GCP infrastructure.
Read the original announcement →
https://docs.cloud.google.com/release-notes#May_09_2026
