Security bulletins

From time to time, we might release security bulletins related to Compute Engine. All security bulletins for Compute Engine are described here.

Use this XML feed to subscribe to Compute Engine security bulletins. Subscribe

GCP-2026-054

Published: 2026-08-11

Description

Description Severity Notes

A vulnerability (CVE-2026-6726, also known as TCGVRT0010) has been identified in the Trusted Computing Group's TPM 2.0 reference implementation code, affecting all published revisions of the code (v1.16, v1.38, v1.59, v1.83, v184).

What should I do?

No customer action is required. Google will proactively update your systems during your standard and planned maintenance windows.

What vulnerabilities are being addressed?

The vulnerability, CVE-2026-6726, could allow a privileged local attacker to obtain credentials from a TPM-aware Certificate Authority (CA) for a falsified TPM key, such as an Attestation Key (AK), a DevID key, or a TLS authentication key. This could enable the creation of fraudulent TPM 2.0 attestations using the forged key.

High CVE-2026-6726

GCP-2026-036

Published: 2026-06-09

Description

Description Severity Notes

ARM has announced CVE-2025-10263, an architectural issue affecting some Arm cores which lets an attacker bypass translation stages or GPT protections under certain conditions. This vulnerability lets an attacker at a lower exception level to write to memory that is owned by a higher exception level, thereby escalating privileges. This issue does not affect memory reads.

While Google has secured the infrastructure against VM-to-VM and VM-to-hypervisor attacks, you must obtain Guest OS-level patches from your OS vendors. These updates are essential for defending against threats within the Guest environment, such as process-to-process or process-to-kernel attacks.

Guest mitigations for Container-Optimized OS are in progress, and will be added to the COS release notes after they are ready.

What should I do?

This vulnerability affects several Arm core families used in Google Cloud, including Neoverse V1, V2, and N1, affecting C4A, T2A, A4X, and A4X Max. If you run workloads on affected Arm-based instances, then you must upgrade your guest OS images to the safe versions as they become available.

You must work with your distro vendors to patch your guest operating system regarding CVE-2025-10263.

High CVE-2025-10263

GCP-2026-032

Published: 2026-05-12

Description

Description Severity Notes

AMD has identified a hardware-level vulnerability in Zen 2 microarchitecture processors (including EPYC and Ryzen series) involving potential corruption within the micro-operation (OP) cache. Under specific conditions, this issue (AMD-SN-7052 / CVE-2025-54518) could lead to security boundary bypasses or unauthorized data access.
We have deployed fixes across Google infrastructure to mitigate these issues.

High CVE-2025-54518

GCP-2026-031

Published: 2026-05-12

Description

Description Severity Notes

Researchers discovered a vulnerability in AMD firmware that, due to missing protection, could allow a malicious hypervisor to execute arbitrary code on the AMD Secure Processor (ASP). This allows for the escalation of Memory Mapped I/O (MMIO) read and write permissions, which compromises the confidentiality and integrity of SEV-SNP guests. Google has applied a mitigation that prevents these issues.

What should I do?

No customer action is needed. Mitigations have already been applied to Confidential VM instances with AMD SEV-SNP.

What vulnerabilities are being addressed?

For more information, see AMD advisory AMD-SB-3030.

Medium

GCP-2026-021

Published: 2026-04-14

Description

Description Severity Notes

AMD reported a vulnerability in its firmware that could have allowed a malicious hypervisor to direct the IOMMU to write into the guest memory of AMD SEV-SNP enabled instances, compromising guest data integrity. Google rolled out a mitigation to vulnerable Confidential VM instances with AMD SEV-SNP enabled.

What should I do?

No customer action is needed. The mitigation has already been applied to Confidential VM instances with AMD SEV-SNP enabled.

For more information, see AMD advisory AMD-SB-3016.

Medium

CVE-2023-20585

GCP-2026-019

Published: 2026-04-14

Description

Description Severity Notes

Researchers discovered a vulnerability in AMD firmware that could allow a malicious hypervisor to alter BIOS settings and Memory Mapped I/O (MMIO) routing configurations, compromising the confidentiality and integrity of Confidential VMs with AMD SEV-SNP guests.

Google implemented the mitigation that prevents this issue.

What should I do?

No customer action is needed. Mitigations have already been applied to Confidential VM instances with AMD SEV-SNP.

What vulnerabilities are being addressed?

For more information, see AMD advisory AMD-SB-3034.

Medium CVE-2025-54510

GCP-2026-015

Published: 2026-03-27

Description

Description Severity Notes

A vulnerability was discovered in the Linux kernel that can lead to a privilege escalation on Container-Optimized OS nodes.

What should I do?

We recommend upgrading your Container-Optimized OS (COS) node to cos-125-19216-220-57, which includes a fix for this vulnerability. For upgrade instructions, see one of the following:

  • If you manage Container-Optimized OS VMs directly, then you should recreate your VMs by using the updated images. For more information, see Creating a VM from a public image.
  • If you use Container-Optimized OS through a managed service (such as GKE, Dataflow, or Cloud SQL), then refer to the specific upgrade instructions for that service.

Note: Fixes are in progress for Container-Optimized OS milestones 117 and 121.

What vulnerabilities are being addressed?

The CrackArmor vulnerability in AppArmor, CVE-2026-23268, allows unprivileged users to bypass kernel protections, escalate to root, and break local container isolation.

High CVE-2026-23268

GCP-2026-004

Published: 2026-01-14

Description

Description Severity Notes

The CPP RCTX instruction on select Arm processors can be used by an attacker with privileged access to the guest kernel to inhibit TLB invalidations from taking effect. This allows the attacker to potentially read sensitive data that they are not authorized to access.

The vulnerability impacts the following Compute Engine Arm VMs: C4A, A4X.

What should I do?

No customer action is required. Mitigations have already been applied to the Google Cloud Arm server fleet.

What vulnerabilities are being addressed?

For more information, please refer to CVE-2025-0647.

Medium CVE-2025-0647

GCP-2025-058

Published: 2025-10-20

Description

Description Severity Notes

A flaw has been discovered in the RDSEED instruction in AMD Zen 5 processors (Turin). This instruction is used to generate cryptographic random numbers. Under certain system load conditions, the 16- and 32-bit versions of RDSEED can silently fail, which could compromise applications relying on random number generation. Customers using the 64-bit version of RDSEED are unaffected.

What should I do?

AMD is investigating the vulnerability.

It's important to note that the 64-bit Linux kernel uses the safe 64-bit version of the RDSEED instruction, and that feeds the random numbers obtained from /dev/[u]random. Those random numbers are not impacted by this vulnerability.

If you have application code that synthesizes random numbers itself using the RDSEED instruction, be aware that the 16-bit and 32-bit versions of the instruction are insecure. The 64-bit version of the instruction is safe.

What vulnerabilites are being addressed?

This vulnerability allows an attacker to cause RDSEED to silently fail, potentially compromising random number generation in applications.

High CVE-2025-62626

GCP-2025-044

Published: 2025-08-12

Description

Description Severity Notes

Intel has notified Google of two new security vulnerabilities.

CVE-2025-21090: This vulnerability affects the following Intel processors:

  • Sapphire Rapids: C3, Z3, H3, A3, v5p VM Families
  • Emerald Rapids: N4, C4, M4, A3 Ultra, A4 VM Families
  • Granite Rapids: N4, C4 VM Family

CVE-2025-22840: This vulnerability affects the following Intel processor:

  • Granite Rapids: N4, C4 VM Family

What should I do?

No customer action is required for either vulnerability. Google will proactively update your systems during your standard and planned maintenance windows. At this time, no evidence of exploitation has been found or reported to Google.

What vulnerabilities are being addressed?

The vulnerability, CVE-2025-21090, allows an unprivileged actor utilizing the AMX CPU instruction, in conjunction with the AVX CPU instruction, to render the host machine inoperative.

The vulnerability, CVE-2025-22840, allows an unprivileged actor utilizing the prefetchit CPU instruction to load memory content it would otherwise not have access to, potentially leading to remote code execution.

Medium

GCP-2025-042

Published: 2025-08-11

Description

Description Severity Notes

Researchers discovered a security vulnerability in specific Intel CPUs, including those based on the Skylake, Broadwell, and Haswell microarchitectures. This vulnerability allows an attacker to potentially read sensitive data directly from the CPU's L1 cache that they are not authorized to access.

This vulnerability was initially disclosed in CVE-2018-3646 in 2018. Upon discovery of this vulnerability, Google immediately implemented mitigations that addressed the known risks. Communication regarding the vulnerability and the initial fixes were published at that time. Since then we have been researching the residual risk and working with the upstream Linux community to remediate this risk.

Recently we worked with security researchers from academia to evaluate the state of the art of CPU security mitigations, and potential attack techniques not considered back in 2018.

Google has applied fixes to the affected assets, including Google Cloud, to mitigate the issue.

What should I do?

No customer action is required. Mitigations have already been applied to the Google server fleet.

What vulnerabilities are being addressed?

For more information, see Intel advisory INTEL-SA-00161 and CVE-2018-3646.

High CVE-2018-3646

GCP-2025-031

Published: 2025-06-10

Description

Description Severity Notes

The Trusted Computing Group (TCG) reported a Trusted Platform Module (TPM) software vulnerability, which affects Shielded VMs using virtual TPM (vTPM). This vulnerability lets an authenticated local attacker read sensitive vTPM data or impact vTPM availability.

vTPM access is usually privileged. However, some configurations may allow broader vTPM access.

What should I do?

No customer action is required. Google will proactively update your systems during your standard and planned maintenance windows. However, you can limit vTPM access to administrative (root) users; this action helps reduce risk to your Shielded VMs.

What vulnerabilities are being addressed?

Vulnerability CVE-2025-2884 lets a local attacker that has vTPM interface access send malicious commands. These commands exploit a mismatch, which reads out-of-bounds (OOB) vTPM memory. This action can expose sensitive data.

High CVE-2025-2884

GCP-2025-025

Published: 2025-05-13

Description

Description Severity Notes

Intel has notified Google about a new side channel vulnerability affecting the following Intel processors: CascadeLake, Ice Lake XeonSP, Ice Lake XeonD, Sapphire Rapids and Emerald Rapids.

Google has applied fixes to the affected assets, including Google Cloud, to ensure customers are protected. At this time, no evidence of exploitation has been found or reported to Google.

What should I do?

No customer action is required. Fixes have already been applied to the Google server fleet to protect customers.

What vulnerabilities are being addressed?

CVE-2024-45332. For more information, see Intel advisory INTEL-SA-01247.

We're here to help

If you have any questions or require assistance, please contact Cloud Customer Care and reference issue number 417536835.

High CVE-2024-45332

GCP-2025-024

Published: 2025-05-12

Updated: 2025-05-13

Description

Description Severity Notes

2025-05-13 Update: If you have any questions or require assistance, please contact Cloud Customer Care and reference issue number 417458390.


Intel has notified Google about a new speculative execution vulnerability affecting Intel Cascade Lake processors and Intel Ice Lake processors.

Google has applied fixes to the affected assets, including Google Cloud, to ensure customers are protected. At this time, no evidence of exploitation has been found or reported to Google.

What should I do?

No customer action is required. Mitigations have already been applied to the Google server fleet.

Further mitigations from Intel Original Equipment Manufacturers (OEMs) and other operating system partners will be deployed as soon as they become available to mitigate the same-mode Indirect Target Selection (ITS) vulnerability.

After the operating system mitigations have been applied, customers with long-running 3rd generation or later VMs may experience some unintended performance degradation

What vulnerabilities are being addressed?

CVE-2024-28956. For more information, see Intel security advisory INTEL-SA-01153.

High CVE-2024-28956

GCP-2024-040

Published: 2024-07-01
Updated: 2024-08-20
Description Severity Notes
Updated: 2024-08-20 Critical CVE-2024-6387

2024-08-20: Include patches for TPUs. Apply updates from Linux distributions as they become available. Please refer to guidance from Linux distributions. If you are using TPUs, please update to one of the following patched versions:

  • tpu-ubuntu2204-base
  • v2-alpha-tpuv5
  • v2-alpha-tpuv5-lite

A vulnerability (CVE-2024-6387) has been discovered in OpenSSH. Successful exploitation of this vulnerability allows a remote, unauthenticated attacker to execute arbitrary code as root on the target machine.

All Compute Engine VMs that use a glibc-based Linux distribution and have OpenSSH exposed are recommended to be analyzed for the vulnerable versions.

What should I do?

  1. Apply updates from Linux distributions as they become available. Please refer to guidance from Linux distributions. For Google's Container-Optimized OS, please update to one of the following patched versions:
    • cos-113-18244-85-49
    • cos-109-17800-218-69
    • cos-105-17412-370-67
    • cos-101-17162-463-55
    If you are using Container-Optimized OS through a Google managed service (e.g. GKE), please refer to that service's security bulletin for patch availability.
  2. If updating is not possible, consider turning OpenSSH off until it can be patched. The default network is pre-populated with a default-allow-ssh firewall rule to allow ssh access from the public Internet. To remove this access, customers can:
    1. Optionally create rules to allow any SSH access you need from trusted networks to GKE nodes or other Compute Engine VMs in the project; then
    2. Disable the default firewall rule with the following command:
      gcloud compute firewall-rules update default-allow-ssh --disabled --project=$PROJECT
            
    If you have created any other firewall rules that may allow SSH through TCP on port 22, disable them, or limit the source IPs to trusted networks.

    Verify that you can no longer ssh to your VMs from the Internet. This firewall configuration mitigates the vulnerability.
  3. If OpenSSH needs to be left on, you can also execute a configuration update which eliminates the race case condition for the exploit. This is a runtime mitigation. To apply the changes in the sshd config, this script will restart the sshd service.
    #!/bin/bash
    set -e
    
    SSHD_CONFIG_FILE=/etc/ssh/sshd_config
    # -c: count the matches
    # -q: don't print to console
    # -i: sshd_config keywords are case insensitive.
    if [[ "$(grep -ci '^LoginGraceTime' $SSHD_CONFIG_FILE)" -eq 0 ]]; then
        echo "LoginGraceTime 0" >> "$SSHD_CONFIG_FILE"
        echo "Set the LoginGraceTime to 0 in $SSHD_CONFIG_FILE"
    else
        sed -i 's/^LoginGraceTime.*$/LoginGraceTime 0/' /etc/ssh/sshd_config
        echo "Changed the LoginGraceTime to 0 in $SSHD_CONFIG_FILE"
    fi
    # Restart the sshd service to apply the new config.
    systemctl restart sshd
        
  4. Finally, monitor for any unusual network activity involving SSH servers.
Critical CVE-2024-6387

GCP-2024-021

Published: 2024-04-03