<?xml version="1.0" encoding="UTF-8"?>

<!-- AUTOGENERATED FILE. DO NOT EDIT. -->

<feed xmlns="http://www.w3.org/2005/Atom">
  <id>tag:google.com,2016:compute-engine-security-bulletins</id>
  <title>Compute Engine - Security Bulletins</title>
  <link rel="self" href="https://docs.cloud.google.com/feeds/compute-engine-security-bulletins.xml"/>
  <author>
    <name>Google Cloud Documentation</name>
  </author>
  <updated>2026-06-09T18:38:16.410220+00:00</updated>


  <entry>
    <title>GCP-2026-036</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2026-036</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-036"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-06-09</p><h3 class="hide-from-toc" data-text="Description" id="description" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>ARM has announced CVE-2025-10263, an architectural issue affecting some Arm cores which allows an attacker to bypass translation stages or GPT protections under certain conditions. This vulnerability allows an attacker at a lower exception level to write to memory owned by a higher exception level, thereby escalating privileges. This issue does not affect memory reads.</p>
<p>While Google has secured the infrastructure against VM-to-VM and VM-to-hypervisor attacks, you must obtain Guest OS-level patches from your OS vendors. These updates are essential for defending against threats within the Guest environment, such as process-to-process or process-to-kernel attacks.</p>
<p>Guest mitigations for Container-Optimized OS are in progress, and will be added to the <a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes">COS release notes</a> once they are ready.</p>
<h4 data-text="What should I do?" id="what-should-i-do" tabindex="-1">What should I do?</h4>
<p>This vulnerability affects several Arm core families used in Google Cloud, including Neoverse V1, V2, and N1, affecting C4A, T2A, A4X, and A4X Max. If you run workloads on affected Arm-based instances, you must upgrade your guest OS images to the safe versions as they become available.</p>
<p>You must work with your distro vendors to patch your guest operating system regarding CVE-2025-10263.</p>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-10263">CVE-2025-10263</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-032</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2026-032</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-032"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-05-12</p><h3 class="hide-from-toc" data-text="Description" id="description_1" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td><p>AMD has identified a hardware-level vulnerability in <strong>Zen 2 microarchitecture processors</strong> (including EPYC and Ryzen series) involving potential corruption within the <strong>micro-operation (OP) cache.</strong> Under specific conditions, this issue (AMD-SN-7052 / CVE-2025-54518) could lead to security boundary bypasses or unauthorized data access.<br/>We have deployed fixes across Google infrastructure to mitigate these issues.</p></td>
<td>High</td>
<td>
<a href="https://www.cve.org/CVERecord?id=CVE-2025-54518">CVE-2025-54518</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-031</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2026-031</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-031"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-05-12</p><h3 class="hide-from-toc" data-text="Description" id="description_2" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Researchers discovered a vulnerability in AMD firmware that, due to missing protection, could allow a malicious hypervisor to execute arbitrary code on the AMD Secure Processor (ASP). This allows for the escalation of Memory Mapped I/O (MMIO) read and write permissions, which compromises the confidentiality and integrity of SEV-SNP guests. Google has applied a mitigation that prevents these issues.</p>
<h4 data-text="What should I do?" id="what-should-i-do_1" tabindex="-1">What should I do?</h4>
<p>No customer action is needed. Mitigations have already been applied to Confidential VM instances with AMD SEV-SNP.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>For more information, see AMD advisory <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3030.html">AMD-SB-3030</a>.</p>
</td>
<td>Medium</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61971">CVE-2025-61971</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61972">CVE-2025-61972</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-36315">CVE-2024-36315</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-021</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2026-021</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-021"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2026-04-14</p><h3 class="hide-from-toc" data-text="Description" id="description_3" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
          AMD reported a vulnerability in its firmware that could have allowed
          a malicious hypervisor to direct the IOMMU to write into the guest
          memory of AMD SEV-SNP enabled instances, compromising guest data
          integrity. Google rolled out a mitigation to vulnerable
          Confidential VM instances with AMD SEV-SNP enabled.
        </p>
<h4 data-text="What should I do?" id="what-should-i-do_2" tabindex="-1">What should I do?</h4>
<p>
          No customer action is needed. The mitigation has already been
          applied to Confidential VM instances with AMD SEV-SNP
          enabled.
        </p>
<p>
          For more information, see AMD advisory
          <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3016.html">
            AMD-SB-3016</a>.
        </p>
</td>
<td>Medium</td>
<td>
<p style="white-space:nowrap">
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-20585">CVE-2023-20585</a>
</p>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-019</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2026-019</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-019"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-04-14</p><h3 class="hide-from-toc" data-text="Description" id="description_4" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Researchers discovered a vulnerability in AMD firmware that could allow a malicious hypervisor to alter BIOS settings and Memory Mapped I/O (MMIO) routing configurations, compromising the confidentiality and integrity of Confidential VMs with AMD SEV-SNP guests.</p>
<p>Google implemented the mitigation that prevents this issue.</p>
<h4 data-text="What should I do?" id="what-should-i-do_3" tabindex="-1">What should I do?</h4>
<p>No customer action is needed. Mitigations have already been applied to Confidential VM instances with AMD SEV-SNP.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_1" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>For more information, see AMD advisory <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3034.html">AMD-SB-3034</a>.</p>
</td>
<td>Medium</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-54510">CVE-2025-54510</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-015</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2026-015</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-015"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-03-27</p><h3 class="hide-from-toc" data-text="Description" id="description_5" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A vulnerability was discovered in the Linux kernel that can lead to a
        privilege escalation on Container-Optimized OS nodes.</p>
<h4 data-text="What should I do?" id="what-should-i-do_4" tabindex="-1">What should I do?</h4>
<p>We recommend upgrading your Container-Optimized OS (COS) node
        to <code dir="ltr" translate="no">cos-125-19216-220-57</code>, which includes a fix for this
        vulnerability. For upgrade instructions, see one of the following:</p>
<ul>
<li>If you manage Container-Optimized OS VMs directly, then you should recreate your
          VMs by using the updated images. For more information, see
          <a href="https://cloud.google.com/compute/docs/instances/create-vm-from-public-image">
          Creating a VM from a public image</a>.</li>
<li>If you use Container-Optimized OS through a managed service
          (such as GKE, Dataflow, or
          Cloud SQL), then refer to the specific upgrade instructions
          for that service.</li>
</ul>
<p class="note"><strong>Note:</strong> Fixes are in progress for
        Container-Optimized OS milestones 117 and 121.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_2" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>The CrackArmor vulnerability in AppArmor, CVE-2026-23268, allows
        unprivileged users to bypass kernel protections, escalate to root, and
        break local container isolation.</p>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-23268">CVE-2026-23268</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2026-004</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2026-004</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2026-004"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2026-01-14</p><h3 class="hide-from-toc" data-text="Description" id="description_6" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>The CPP RCTX instruction on select Arm processors can be used by an
        attacker with privileged access to the guest kernel to inhibit TLB
        invalidations from taking effect. This allows the attacker to
        potentially read sensitive data that they are not authorized to access.</p>
<p>The vulnerability impacts the following Compute Engine Arm VMs: C4A, A4X.</p>
<h4 data-text="What should I do?" id="what-should-i-do_5" tabindex="-1">What should I do?</h4>
<p>No customer action is required. Mitigations have already been applied
        to the Google Cloud Arm server fleet.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_3" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>For more information, please refer to
        <a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0647">CVE-2025-0647</a>.</p>
</td>
<td>Medium</td>
<td>
<a href="https://nvd.nist.gov/vuln/detail/CVE-2025-0647">CVE-2025-0647</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-058</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2025-058</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2025-058"/>
    <content type="html"><![CDATA[<p><strong>Published:</strong> 2025-10-20</p><h3 class="hide-from-toc" data-text="Description" id="description_7" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
<a href="https://lore.kernel.org/lkml/20251016182107.3496116-1-gourry@gourry.net/">
          A flaw has been discovered in the RDSEED instruction</a> in AMD Zen 5
          processors (Turin). This instruction is used to generate cryptographic
          random numbers. Under certain system load conditions, the 16- and
          32-bit versions of RDSEED can silently fail, which could compromise
          applications relying on random number generation. Customers using the
          64-bit version of RDSEED are unaffected.
        </p>
<h4 data-text="What should I do?" id="what-should-i-do_6" tabindex="-1">What should I do?</h4>
<p>AMD is investigating the vulnerability.</p>
<p>
          It's important to note that the 64-bit Linux kernel uses the safe
          64-bit version of the RDSEED instruction, and that feeds the random
          numbers obtained from <code dir="ltr" translate="no">/dev/[u]random</code>. Those random
          numbers are not impacted by this vulnerability.
        </p>
<p>
          If you have application code that synthesizes random numbers itself
          using the RDSEED instruction, be aware that the 16-bit and 32-bit
          versions of the instruction are insecure. The 64-bit version of the
          instruction is safe.
        </p>
<h4 data-text="What vulnerabilites are being addressed?" id="what-vulnerabilites-are-being-addressed" tabindex="-1">What vulnerabilites are being addressed?</h4>
<p>
          This vulnerability allows an attacker to cause RDSEED to silently
          fail, potentially compromising random number generation in
          applications.
        </p>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-62626">CVE-2025-62626</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-044</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2025-044</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2025-044"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-08-12</p><h3 class="hide-from-toc" data-text="Description" id="description_8" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Intel has notified Google of two new security vulnerabilities.</p>
<p>CVE-2025-21090: This vulnerability affects the following Intel processors:</p>
<ul>
<li>Sapphire Rapids: C3, Z3, H3, A3, v5p VM Families</li>
<li>Emerald Rapids: N4, C4, M4, A3 Ultra, A4 VM Families</li>
<li>Granite Rapids: N4, C4 VM Family</li>
</ul>
<p>CVE-2025-22840: This vulnerability affects the following Intel processor:</p>
<ul>
<li>Granite Rapids: N4, C4 VM Family</li>
</ul>
<h4 data-text="What should I do?" id="what-should-i-do_7" tabindex="-1">What should I do?</h4>
<p>No customer action is required for either vulnerability. Google will proactively update your systems during your standard and planned maintenance windows. At this time, no evidence of exploitation has been found or reported to Google.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_4" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>The vulnerability, <a href="https://www.cve.org/CVERecord?id=CVE-2025-21090">CVE-2025-21090</a>, allows an unprivileged actor utilizing the AMX CPU instruction, in conjunction with the AVX CPU instruction, to render the host machine inoperative.</p>
<p>The vulnerability, <a href="https://www.cve.org/CVERecord?id=CVE-2025-22840">CVE-2025-22840</a>, allows an unprivileged actor utilizing the prefetchit CPU instruction to load memory content it would otherwise not have access to, potentially leading to remote code execution.</p>
</td>
<td>Medium</td>
<td>
<ul>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-21090">CVE-2025-21090</a></li>
<li><a href="https://www.cve.org/CVERecord?id=CVE-2025-22840">CVE-2025-22840</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-042</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2025-042</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2025-042"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-08-11</p><h3 class="hide-from-toc" data-text="Description" id="description_9" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><a href="https://openreview.net/forum?id=4tDNvQe2G0">Researchers</a> discovered a security vulnerability in specific Intel CPUs, including those based on the Skylake, Broadwell, and Haswell microarchitectures. This vulnerability allows an attacker to potentially read sensitive data directly from the CPU's L1 cache that they are not authorized to access.</p>
<p>This vulnerability was initially disclosed in <a href="https://nvd.nist.gov/vuln/detail/cve-2018-3646">CVE-2018-3646</a> in 2018. Upon discovery of this vulnerability, Google immediately implemented mitigations that addressed the known risks. Communication regarding the vulnerability and the initial fixes were <a href="https://cloud.google.com/blog/products/gcp/protecting-against-the-new-l1tf-speculative-vulnerabilities">published at that time</a>. Since then we have been researching the residual risk and working with the upstream Linux community to remediate this risk.</p>
<p>Recently we worked with security researchers from academia to evaluate the state of the art of CPU security mitigations, and potential attack techniques not considered back in 2018.</p>
<p>Google has applied fixes to the affected assets, including Google Cloud, to mitigate the issue.</p>
<h4 data-text="What should I do?" id="what-should-i-do_8" tabindex="-1">What should I do?</h4>
<p>No customer action is required. Mitigations have already been applied to the Google server fleet.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_5" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>For more information, see Intel advisory <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00161.html">INTEL-SA-00161</a> and CVE-2018-3646.</p>
</td>
<td>High</td>
<td>
<a href="https://nvd.nist.gov/vuln/detail/cve-2018-3646">CVE-2018-3646</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-031</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2025-031</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2025-031"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-06-10</p><h3 class="hide-from-toc" data-text="Description" id="description_10" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>The <a href="https://trustedcomputinggroup.org/">Trusted Computing
      Group (TCG)</a> reported a Trusted Platform Module (TPM) software
      vulnerability, which affects
      <a href="https://cloud.google.com/security/shielded-cloud/shielded-vm">
      Shielded VMs</a> using virtual TPM (vTPM). This vulnerability lets an
      authenticated local attacker read sensitive vTPM data or impact vTPM
      availability.</p>
<p>vTPM access is usually privileged. However, some configurations may
      allow broader vTPM access.</p>
<h4 data-text="What should I do?" id="what-should-i-do_9" tabindex="-1">What should I do?</h4>
<p>No customer action is required. Google will proactively update your
      systems during your standard and planned maintenance windows. However, you
      can limit vTPM access to administrative (root) users; this action helps
      reduce risk to your Shielded VMs.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_6" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>Vulnerability <a href="https://www.cve.org/CVERecord?id=CVE-2025-2884">
      CVE-2025-2884</a> lets a local attacker that has vTPM interface access
      send malicious commands. These commands exploit a mismatch, which reads
      out-of-bounds (OOB) vTPM memory. This action can expose sensitive data.
      </p>
</td>
<td>High</td>
<td>
<a href="https://www.cve.org/CVERecord?id=CVE-2025-2884">CVE-2025-2884</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-025</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2025-025</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2025-025"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-05-13</p><h3 class="hide-from-toc" data-text="Description" id="description_11" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td><p>Intel has notified Google about a new side channel vulnerability
      affecting the following Intel processors: CascadeLake, Ice Lake XeonSP,
      Ice Lake XeonD, Sapphire Rapids and Emerald Rapids.</p>
<p>Google has applied fixes to the affected assets, including
      Google Cloud, to ensure customers are protected. At this time, no evidence
      of exploitation has been found or reported to Google.</p>
<h4 data-text="What should I do?" id="what-should-i-do_10" tabindex="-1">What should I do?</h4>
<p>No customer action is required. Fixes have already been applied to the
      Google server fleet to protect customers.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_7" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45332">CVE-2024-45332</a>.
      For more information, see
      <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01247.html">Intel advisory INTEL-SA-01247</a>.</p>
<h4 data-text="We're here to help" id="were-here-to-help" tabindex="-1">We're here to help</h4>
<p>If you have any questions or require assistance, please contact
      <a href="https://docs.cloud.google.com/support/docs/overview">Cloud Customer Care</a> and reference issue
      number 417536835.</p>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-45332">CVE-2024-45332</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2025-024</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2025-024</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2025-024"/>
    <content type="html"><![CDATA[<p><strong>Published: </strong>2025-05-12</p><p><strong>Updated: </strong>2025-05-13</p><h3 class="hide-from-toc" data-text="Description" id="description_12" tabindex="-1">Description</h3><table>
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><strong>2025-05-13 Update:</strong> If you have any questions or
        require assistance, please contact
        <a href="https://docs.cloud.google.com/support/docs/overview">Cloud Customer Care</a> and reference
        issue number 417458390.</p>
<hr/>
<p>Intel has notified Google about a new speculative execution
        vulnerability affecting Intel Cascade Lake processors and Intel Ice Lake
        processors.</p>
<p>Google has applied fixes to the affected assets, including
        Google Cloud, to ensure customers are protected. At this time, no
        evidence of exploitation has been found or reported to Google.</p>
<h4 data-text="What should I do?" id="what-should-i-do_11" tabindex="-1">What should I do?</h4>
<p>No customer action is required. Mitigations have already been applied
        to the Google server fleet.</p>
<p>Further mitigations from Intel Original Equipment Manufacturers
        (OEMs) and other operating system partners will be deployed as soon as
        they become available to mitigate the same-mode Indirect Target Selection
        (ITS) vulnerability.</p>
<p>After the operating system mitigations have been applied, customers
        with long-running 3rd generation or later VMs may experience some
        unintended performance degradation</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_8" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p>CVE-2024-28956. For more information, see
        <a href="https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/advisory-guidance/indirect-target-selection.html">Intel security advisory INTEL-SA-01153</a>.</p>
</td>
<td>High</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28956">CVE-2024-28956</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2024-040</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2024-040</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2024-040"/>
    <content type="html"><![CDATA[<strong>Published:</strong><br/><strong>Updated:</strong><br/><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>Updated: 2024-08-20</strong></td>
<td><strong>Critical</strong></td>
<td><strong>CVE-2024-6387</strong></td>
</tr>
<td>
<p><strong>2024-08-20: Include patches for TPUs.</strong>
    Apply updates from Linux distributions as they become available. Please
    refer to guidance from Linux distributions. If you are using TPUs, please
    update to one of the following patched versions:</p>
<ul>
<li>tpu-ubuntu2204-base</li>
<li>v2-alpha-tpuv5</li>
<li>v2-alpha-tpuv5-lite</li>
</ul>
<p>A vulnerability (CVE-2024-6387) has been discovered in OpenSSH. Successful
  exploitation of this vulnerability allows a remote, unauthenticated attacker
  to execute arbitrary code as root on the target machine.
  <br/><br/>
  All Compute Engine VMs that use a glibc-based Linux distribution and have OpenSSH exposed
  are recommended to be analyzed for the vulnerable versions.
  </p>
<h4 data-text="What should I do?" id="what-should-i-do_12" tabindex="-1">What should I do?</h4>
<ol>
<li>Apply updates from Linux distributions as they become available. Please
    refer to guidance from Linux distributions. For Google's Container-Optimized OS, please update to one of the following patched versions:
    <ul>
<li>cos-113-18244-85-49</li>
<li>cos-109-17800-218-69</li>
<li>cos-105-17412-370-67</li>
<li>cos-101-17162-463-55</li>
</ul>
    If you are using Container-Optimized OS through a Google managed service
    (e.g. GKE), please refer to that service's security bulletin for patch
    availability.
    </li>
<li>If updating is not possible, consider turning OpenSSH off until it can
    be patched. The default network is pre-populated with a
    <code dir="ltr" translate="no">default-allow-ssh</code> firewall rule to allow ssh access from the
    public Internet. To remove this access, customers can:
  <ol>
<li>Optionally <a href="https://docs.cloud.google.com/firewall/docs/using-firewalls#creating_firewall_rules">create rules</a> to allow any SSH
      access you need from trusted networks to GKE nodes or other Compute Engine VMs in the
      project; then</li>
<li>Disable the default firewall rule with the following command:
      <div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no">gcloud compute firewall-rules update default-allow-ssh --disabled --project=$PROJECT
      </pre></devsite-code></li>
</ol>
    If you have created any other firewall rules that may allow SSH through
    TCP on port 22, disable them, or limit the source IPs to trusted networks.
    <br/><br/>
    Verify that you can no longer ssh to your VMs from the Internet.
    This firewall configuration mitigates the vulnerability.
    </li>
<li>If OpenSSH needs to be left on, you can also execute a configuration
    update which eliminates the race case condition for the exploit. This is a
    runtime mitigation. To apply the changes in the sshd config, this script
    will restart the sshd service.
    <div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no">
#!/bin/bash
set -e

SSHD_CONFIG_FILE=/etc/ssh/sshd_config
# -c: count the matches
# -q: don't print to console
# -i: sshd_config keywords are case insensitive.
if [[ "$(grep -ci '^LoginGraceTime' $SSHD_CONFIG_FILE)" -eq 0 ]]; then
    echo "LoginGraceTime 0" &gt;&gt; "$SSHD_CONFIG_FILE"
    echo "Set the LoginGraceTime to 0 in $SSHD_CONFIG_FILE"
else
    sed -i 's/^LoginGraceTime.*$/LoginGraceTime 0/' /etc/ssh/sshd_config
    echo "Changed the LoginGraceTime to 0 in $SSHD_CONFIG_FILE"
fi
# Restart the sshd service to apply the new config.
systemctl restart sshd
    </pre></devsite-code></li>
<li>Finally, monitor for any unusual network activity involving SSH servers.
    </li>
</ol>
</td>
<td>
Critical
</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6387">CVE-2024-6387</a>
</td>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2024-021</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2024-021</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2024-021"/>
    <content type="html"><![CDATA[<strong>Published:</strong><br/><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Compute Engine is not affected by
  <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3094">CVE-2024-3094</a>,
  which affects versions 5.6.0 and 5.6.1 of the xz-utils package in the liblzma
  library, and could lead to compromise of the OpenSSH utility.</p>
<h4 data-text="What should I do?" id="what-should-i-do_13" tabindex="-1">What should I do?</h4>
<p><a href="https://docs.cloud.google.com/compute/docs/images/os-details">Public images supported and offered by Compute Engine</a>
  are not affected by this CVE. If you use Compute Engine public images for your
  VMs, no action is required.</p>
<p>You could be at risk if you created a
  <a href="https://docs.cloud.google.com/compute/docs/images#custom_images">custom image</a> that used
  versions 5.6.0 and 5.6.1 of xz-utils package, such as the following operating
  systems:</p>
<ul>
<li><a href="https://www.redhat.com/en/blog/urgent-security-alert-fedora-41-and-rawhide-users">
  Fedora 41 and Fedora Rawhide</a></li>
<li><a href="https://lists.debian.org/debian-security-announce/2024/msg00057.html">
  Debian testing/unstable</a></li>
<li><a href="https://news.opensuse.org/2024/03/29/xz-backdoor/">openSUSE tumbleweed</a></li>
</ul>
<p>To mitigate this risk,
  <a href="https://docs.cloud.google.com/compute/docs/instances/stop-start-instance#stop-vm">stop any VMs</a>
  that use these operating systems or others that could have used affected
  operating systems. If you have VMs built from custom images of other
  operating systems, check with your OS vendor to see if your VMs are affected.</p>
<h4 data-text="What vulnerabilities are being addressed?" id="what-vulnerabilities-are-being-addressed_9" tabindex="-1">What vulnerabilities are being addressed?</h4>
<p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3094">CVE-2024-3094</a></p>
</td>
<td>
Medium
</td>
<td>
<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-3094">CVE-2024-3094</a>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2024-001</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2024-001</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2024-001"/>
    <content type="html"><![CDATA[<strong>Published:</strong><br/><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Several vulnerabilities were discovered in the TianoCore EDK II UEFI
  firmware. This firmware is used in Google Compute Engine VMs. If exploited,
  the vulnerabilities could allow a bypass of secure boot, which would provide
  false measurements in the secure boot process, including when used in Shielded
  VMs.</p>
<h4 data-text="What should I do?" id="what-should-i-do_14" tabindex="-1">What should I do?</h4>
<p>No action is required. Google has patched this vulnerability across
  Compute Engine and all VMs are protected from this vulnerability.</p>
<h4 data-text="What vulnerabilities are addressed by this patch?" id="what-vulnerabilities-are-addressed-by-this-patch" tabindex="-1">What vulnerabilities are addressed by this patch?</h4>
<p>The patch mitigated the following vulnerabilities:</p>
<ul>
<li>CVE-2022-36763</li>
<li>CVE-2022-36764</li>
<li>CVE-2022-36765</li>
</ul>
</td>
<td>
Medium
</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-36763" target="mitre">CVE-2022-36763</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-36764" target="mitre">CVE-2022-36764</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-36765" target="mitre">CVE-2022-36765</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2023-44</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2023-44</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2023-44"/>
    <content type="html"><![CDATA[<strong>Published:</strong><br/><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>On November 14, AMD disclosed multiple vulnerabilities that impact various
  AMD server CPUs. Specifically, the vulnerabilities impact EPYC Server CPUs
  leveraging Zen core generation 2 "Rome," gen 3 "Milan," and gen 4 "Genoa."</p>
<p>Google has applied fixes to affected assets, including Google Cloud, to ensure
customers are protected. At this time, no evidence of exploitation has been
found or reported to Google. </p>
<h4 data-text="What should I do?" id="what-should-i-do_15" tabindex="-1">What should I do?</h4>
<p>No customer action is required.</p>
<p>Fixes have already been applied to the Google server fleet for Google Cloud, including Google Compute Engine. </p>
<h4 data-text="What vulnerabilities are addressed by this patch?" id="what-vulnerabilities-are-addressed-by-this-patch_1" tabindex="-1">What vulnerabilities are addressed by this patch?</h4>
<p>The patch mitigated the following vulnerabilities:</p>
<ul>
<li>CVE-2022-23820</li>
<li>CVE-2021-46774</li>
<li>CVE-2023-20533</li>
<li>CVE-2023-20519</li>
<li>CVE-2023-20592</li>
<li>CVE-2023-20566</li>
<li>CVE-2023-20521</li>
<li>CVE-2021-46766</li>
<li>CVE-2022-23830</li>
<li>CVE-2023-20526</li>
<li>CVE-2021-26345</li>
</ul>
<p>For more information, see AMD's security advisory <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3005.html">AMD-SN-3005: "AMD INVD Instruction Security Notice"</a>, also
  published as CacheWarp, and <a href="https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3002.html">AMD-SN-3002: "AMD Server Vulnerabilities – November
  2023"</a>.</p>
</td>
<td>
Medium
</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23820" target="mitre">CVE-2022-23820</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-46774" target="mitre">CVE-2021-46774</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20533" target="mitre">CVE-2023-20533</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20519" target="mitre">CVE-2023-20519</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20592" target="mitre">CVE-2023-20592</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20566" target="mitre">CVE-2023-20566</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2022-23830" target="mitre">CVE-2022-23830</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-20526" target="mitre">CVE-2023-20526</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-26345" target="mitre">CVE-2021-26345</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2023-004</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2023-004</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2023-004"/>
    <content type="html"><![CDATA[<strong>Published:</strong><br/><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Two vulnerabilities
    (<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-1017">CVE-2023-1017</a>
    and
    <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-1018">CVE-2023-1018</a>)
    were discovered in Trusted Platform Module (TPM) 2.0.</p>
<p>The vulnerabilities could have allowed a sophisticated attacker to
    exploit a 2-byte out of bounds read/write on certain Compute Engine
    VMs.</p>
<h4 data-text="What should I do?" id="what-should-i-do_16" tabindex="-1">What should I do?</h4>
<p>A patch was automatically applied to all vulnerable VMs. No customer action
  is required.</p>
<h4 data-text="What vulnerabilities are addressed by this patch?" id="what-vulnerabilities-are-addressed-by-this-patch_2" tabindex="-1">What vulnerabilities are addressed by this patch?</h4>
<p>The patch mitigated the following vulnerabilities:</p>
<h5 data-text="CVE-2023-1017" id="cve-2023-1017" tabindex="-1">CVE-2023-1017</h5>
<p>With CVE-2023-2017, a buffer overrun could be triggered in the vTPM
  parameter decryption routine. A local attacker running on a vulnerable VM
  could use this to trigger a denial-of-service or possibly execute arbitrary
  code in the vTPM context.</p>
<h5 data-text="CVE-2023-1018" id="cve-2023-1018" tabindex="-1">CVE-2023-1018</h5>
<p>With CVE-2023-2018, an out-of-bounds read existed in the vTPM parameter
  decryption routine. A local attacker running on a vulnerable VM could use this
  to indirectly leak limited data from the vTPM context.</p>
</td>
<td>
Medium
</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-1017" target="mitre">CVE-2023-1017</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2023-1018" target="mitre">CVE-2023-1018</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2021-026</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2021-026</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2021-026"/>
    <content type="html"><![CDATA[<strong>Published:</strong><br/><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>The Apache Log4j utility is a commonly used component for logging
     requests. On December 9, 2021, a vulnerability was reported that could
     allow a system running Apache Log4j version 2.14.1 or below to be
     compromised and allow an attacker to execute arbitrary code.</p>
<p>On December 10, 2021, NIST published a critical Common Vulnerabilities
     and Exposure alert,
     <a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44228">CVE-2021-44228</a>.
     More specifically, Java Naming Directory Interface (JNDI) features used in
     configuration, log messages, and parameters don't protect against
     attacker controlled LDAP and other JNDI related endpoints. An attacker
     who can control log messages or log message parameters can execute
     arbitrary code loaded from remote servers when message lookup
     substitution is enabled.</p>
<h4 data-text="What should I do?" id="what-should-i-do_17" tabindex="-1">What should I do?</h4>
<ul>
<li><strong>M4CE v4.x:</strong> The Migrate for Compute Engine (M4CE) Team
   has provided a new version on 13 December, 2021. Project managers are
    required to replace the existing deployment with the new version including
     in-cloud M4CE Manager and M4CE "on premises" backend. See
     the <a href="https://docs.cloud.google.com/migrate/compute-engine/docs/4.11/how-to">How to Guide</a>
      for details on version 4.11 deploy details.</li>
<li><strong>M2VMs v5.x:</strong> M2VMs v5.0 and above has been fixed and no
      action is required.</li>
</ul>
</td>
<td>
Critical
</td>
<td>
<ul>
<li><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44228" target="mitre">CVE-2021-44228</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>GCP-2021-001</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#gcp-2021-001</id>
    <updated>2026-06-09T18:38:16.410220+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#gcp-2021-001"/>
    <content type="html"><![CDATA[<strong>Published:</strong><br/><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>A vulnerability was recently discovered in the Linux utility <code dir="ltr" translate="no">sudo</code>,
        described in <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2021-3156">CVE-2021-3156</a>,
        that might allow an attacker with unprivileged local shell access on a
        system with <code dir="ltr" translate="no">sudo</code> installed to escalate their privileges to
        root on the system.</p>
<h4 data-text="Compute Engine impact" id="compute-engine-impact" tabindex="-1">Compute Engine impact</h4>
<p>The underlying infrastructure that runs Compute Engine is not
       impacted by this vulnerability. Compute Engine VMs running Linux
       should consider updating their guest operating system. For example, if
       you use a
       <a href="https://docs.cloud.google.com/container-optimized-os/docs/release-notes">Container-Optimized OS</a>,
       we recommend you update to one of the following images:
       cos-85-13310-1209-7, cos-81-12871-1245-6, cos-dev-89-16091-0-0, or
       later.</p>
</td>
<td>
None
</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-3156" target="mitre">CVE-2021-3156</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>Date published: 2020-08-27</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#20200827</id>
    <updated>2020-08-27T00:00:00+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#20200827"/>
    <content type="html"><![CDATA[<table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
    Eclypsium has disclosed the following CVE: <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-10713">CVE-2020-10713</a>.
  </p>
<h4 data-text="Vulnerabilities" id="vulnerabilities" tabindex="-1">Vulnerabilities</h4>
<p>In response to the initial vulnerability report, additional scrutiny was
  applied to the GRUB2 code and the following additional vulnerabilities were
  discovered by Canonical:</p>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-14308">CVE-2020-14308</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-14309">CVE-2020-14309</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-14310">CVE-2020-14310</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-14311">CVE-2020-14311</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-15705">CVE-2020-15705</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-15706">CVE-2020-15706</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-15707">CVE-2020-15707</a></li>
</ul>
<p>These vulnerabilities, collectively referred to as BootHole, allow unsigned
  binaries to be loaded by attackers with administrative privileges, thus
  disabling secure boot enforcement.</p>
<h4 data-text="Compute Engine impact" id="compute-engine-impact_1" tabindex="-1">Compute Engine impact</h4>
<p> The host infrastructure that runs Compute Engine is protected
  against known attacks. </p>
<p>Compute Engine customers who use <a href="https://cloud.google.com/security/shielded-cloud/shielded-vm#secure-
  boot">secure boot</a> are encouraged to update the guest operating systems on
  their instances to prevent the possibility of exploitation within their guest
  environments. For details, refer to your Guest OS Vendor's recommended
  mitigation.</p>
<h4 data-text="Patched images and vendor resources" id="patched-images-and-vendor-resources" tabindex="-1">Patched images and vendor resources</h4>
<p>We will provide links to patch information from each operating system
  vendor here as they become available. Earlier versions of these public images
  don't contain these patches and don't mitigate potential attacks:</p>
<ul>
<li>Project <code dir="ltr" translate="no">centos-cloud</code>: <a href="https://lists.centos.org/pipermail/centos-announce/2020-July/035778.html">CentOS patch information</a>
<ul>
<li><code dir="ltr" translate="no">centos-7-v20200811</code></li>
<li><code dir="ltr" translate="no">centos-8-v20200811</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">cos-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">cos-77-12371-1072-0</code></li>
<li><code dir="ltr" translate="no">cos-81-12871-1185-0</code></li>
<li><code dir="ltr" translate="no">cos-rc-85-13310-1028-0</code></li>
<li><code dir="ltr" translate="no">cos-dev-86-15103-0-0</code></li>
</ul>
<p>If you are using COS through a managed service (e.g. GKE), please
      follow the guidance for that service to apply updates.</p>
</li>
<li>Project <code dir="ltr" translate="no">debian-cloud</code>: <a href="https://www.debian.org/security/2020/dsa-4735">DSA-4753</a>
<ul>
<li><code dir="ltr" translate="no">debian-10-buster-v20200805</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">coreos-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">coreos-alpha-2163-2-1-v20190617</code></li>
<li><code dir="ltr" translate="no">coreos-beta-2135-3-1-v20190617</code></li>
<li><code dir="ltr" translate="no">coreos-stable-2079-6-0-v20190617</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">rhel-cloud/rhel-sap-cloud:</code> <a href="https://access.redhat.com/security/vulnerabilities/grub2bootloader">Red Hat Vulnerability Response</a>
<ul>
<li><code dir="ltr" translate="no">rhel-7-v20200811</code></li>
<li><code dir="ltr" translate="no">rhel-7-4-sap-v20200811</code></li>
<li><code dir="ltr" translate="no">rhel-7-6-sap-v20200811</code></li>
<li><code dir="ltr" translate="no">rhel-7-7-sap-v20200811</code></li>
<li><code dir="ltr" translate="no">rhel-8-v20200811</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">suse-cloud/suse-sap-cloud:</code>: <a href="https://www.suse.com/support/kb/doc/?id=000019673">SUSE KB</a>
<ul>
<li><code dir="ltr" translate="no">sles-12-sp5-v20200813</code></li>
<li><code dir="ltr" translate="no">sles-15-sp2-v20200804</code></li>
<li><code dir="ltr" translate="no">sles-12-sp4-sap-v20200804</code></li>
<li><code dir="ltr" translate="no">sles-12-sp5-sap-v20200813</code></li>
<li><code dir="ltr" translate="no">sles-15-sap-v20200803</code></li>
<li><code dir="ltr" translate="no">sles-15-sp1-sap-v20200803</code></li>
<li><code dir="ltr" translate="no">Sles-15-sp2-sap-v20200804</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">ubuntu-os-cloud</code>: <a href="https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/GRUB2SecureBootBypass">Ubuntu Wiki</a>
<ul>
<li><code dir="ltr" translate="no">ubuntu-1604-xenial-v20200729</code></li>
<li><code dir="ltr" translate="no">ubuntu-1804-bionic-v20200729</code></li>
<li><code dir="ltr" translate="no">ubuntu-2004-focal-v20200729</code></li>
</ul>
</li>
</ul>
</td>
<td>
      High
    </td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-10713">CVE-2020-10713</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-14308">CVE-2020-14308</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-14309">CVE-2020-14309</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-14310">CVE-2020-14310</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-14311">CVE-2020-14311</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-15705">CVE-2020-15705</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-15706">CVE-2020-15706</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2020-15707">CVE-2020-15707</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>Date published: 2020-06-19</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#20200619</id>
    <updated>2020-06-19T00:00:00+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#20200619"/>
    <content type="html"><![CDATA[<table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>
  VMs that have OS Login enabled might be susceptible to privilege
  escalation vulnerabilities. These vulnerabilities gives users that are granted
  OS Login permissions (but not given administrator access) the ability to escalate
  to root access in the VM.
  </p>
<h4 data-text="Vulnerabilities" id="vulnerabilities_1" tabindex="-1">Vulnerabilities</h4>
<p>
    The following three vulnerabilities, which are due to overly permissive
    default group memberships, were identified for Compute Engine images:
  </p>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8903">CVE-2020-8903</a>:
  by using the <code dir="ltr" translate="no">adm</code> user, you can take advantage of the DHCP XID
  to obtain administrative privileges.</li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8907">CVE-2020-8907</a>:
  by using the <code dir="ltr" translate="no">docker</code> user, you can mount and modify
  the host OS file system to obtain administrative privileges.</li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8933">CVE-2020-8933</a>:
  by using the <code dir="ltr" translate="no">lxd</code> user, you can attach host OS file
  systems and obtain administrative privileges.</li>
</ul>
<h4 data-text="Patched images and fixes" id="patched-images-and-fixes" tabindex="-1">Patched images and fixes</h4>
<p>
  All Compute Engine public images created after <code dir="ltr" translate="no">v20200506</code>
  are patched.</p>
<p>
   If you need to fix this issue without updating to a later version of your
  image, you can edit the <code dir="ltr" translate="no">/etc/security/group.conf</code> file and remove
  the <code dir="ltr" translate="no">adm</code>, <code dir="ltr" translate="no">lxd</code> and <code dir="ltr" translate="no">docker</code> users from the
  default OS Login entry.
  </p>
</td>
<td>
  High
</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8903" target="mitre">CVE-2020-8903</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8907" target="mitre">CVE-2020-8907</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8933" target="mitre">CVE-2020-8933</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>Date published: 2020-01-21</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#20200121</id>
    <updated>2020-01-21T00:00:00+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#20200121"/>
    <content type="html"><![CDATA[<table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Microsoft disclosed the following vulnerability:</p>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0601" target="mitre">CVE-2020-0601</a>—
          This vulnerability is also known as the Windows Crypto API Spoofing
          Vulnerability and could be exploited to make malicious executables
          appear trusted or allow the attacker to conduct man-in-the-middle
          attacks and decrypt confidential information on user connections to
          the affected software.
        </li>
</ul>
<h4 data-text="Compute Engine impact" id="20200121_impact" tabindex="-1">Compute Engine impact</h4>
<p>The underlying infrastructure that runs Compute Engine is not
  impacted by this vulnerability. Unless you are running Windows Server in
  your Compute Engine virtual machine, no further action is required.
  Customers using Compute Engine VMs running Windows Server should
        ensure their instances have the latest Windows patch.</p>
<h4 data-text="Patched images and vendor resources" id="patched-images-and-vendor-resources_1" tabindex="-1">Patched images and vendor resources</h4>
<p>Earlier versions of the public Windows images don't contain the following
    patches and don't mitigate potential attacks:</p>
<ul>
<li>Projects <code dir="ltr" translate="no">windows-cloud</code> and <code dir="ltr" translate="no">windows-sql-cloud</code>
<ul>
<li>All Windows Server and SQL Server public images starting from
        v20200114</li>
</ul>
</li>
</ul>
</td>
<td>
  Medium
</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-0601" target="mitre">CVE-2020-0601</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>Date published: 2019-11-12</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#20191112</id>
    <updated>2019-11-12T00:00:00+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#20191112"/>
    <content type="html"><![CDATA[<table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Intel has disclosed the following CVEs:</p>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-11135" target="mitre">CVE-2019-11135</a>—
          This CVE is also known as TSX Async Abort (TAA). TAA provides another
          avenue for data exfiltration using the same microarchitectural data
          structures that were exploited by Microarchitectural Data Sampling
          (MDS).
        </li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-12207" target="mitre">CVE-2018-12207</a>—
          This CVE is also known as "Machine Check Error on Page Size Change."
          This is a Denial of Service (DoS) vulnerability affecting virtual
          machine hosts allowing a malicious guest to crash an unprotected host.</li>
</ul>
<h4 data-text="Compute Engine impact" id="20191112_impact" tabindex="-1">Compute Engine impact</h4>
<h5 data-text="CVE-2019-11135" id="cve-2019-11135" tabindex="-1">CVE-2019-11135</h5>
<p>The host infrastructure that runs Compute Engine isolates customer
       workloads. Unless you are running untrusted code inside N2, C2, or M2 VMs,
       no further action is required.</p>
<p>N2, C2, or M2 customers running untrusted code in their own multi-tenant
     services within Compute Engine virtual machines should
     <a href="https://docs.cloud.google.com/compute/docs/instances/stop-start-instance">stop and start</a>
     their VMs in order to ensure they have the latest security mitigations. A
     reboot, without a stop/start, is not sufficient. This guidance assumes you
     have already applied previously released updates covering the MDS
     vulnerability. If not, please
     <a href="https://docs.cloud.google.com/compute/docs/security-bulletins#20190514">follow the instructions</a>
     to apply the appropriate updates.</p>
<p>For customers running N1 machine types, no action is required, as this
       vulnerability does not represent new exposure beyond the
       previously disclosed MDS vulnerabilities.</p>
<h5 data-text="CVE-2018-12207" id="cve-2018-12207" tabindex="-1">CVE-2018-12207</h5>
<p>The host infrastructure that runs Compute Engine is protected from
       this vulnerability.  No further action is required.</p>
</td>
<td>
  Medium
</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11135" target="mitre">CVE-2019-11135</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12207" target="mitre">CVE-2018-12207</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>Date published: 2019-06-18</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#20190618</id>
    <updated>2019-06-18T00:00:00+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#20190618"/>
    <content type="html"><![CDATA[<p><strong>last updated: 2019-06-25 T 6:30 PST</strong></p><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Netflix has recently disclosed three TCP vulnerabilities in Linux kernels:</p>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11477" target="mitre">CVE-2019-11477</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11478" target="mitre">CVE-2019-11478</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11479" target="mitre">CVE-2019-11479</a></li>
</ul>
<p>These CVEs are collectively referred to as
    <a href="https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-001.md" target="github">NFLX-2019-001</a>.</p>
<h4 data-text="Compute Engine impact" id="20190618_impact" tabindex="-1">Compute Engine impact</h4>
<p>The infrastructure that hosts Compute Engine is protected from
       this vulnerability.</p>
<p>Compute Engine VMs running unpatched Linux operating systems
       that send/receive untrusted network traffic are vulnerable to this DoS
       attack. Consider updating these VM instances as soon as patches are
       available for their operating systems.</p>
<p>Load balancers that close TCP connections have been patched
       against this vulnerability. Compute Engine instances that
       receive only untrusted traffic through these load balancers are not
       vulnerable. This includes HTTP Load Balancers, SSL Proxy Load Balancers,
       and TCP Proxy Load Balancers.
     </p>
<p>Network load balancers and internal load balancers don't close TCP
       connections. Unpatched Compute Engine instances that receive
       untrusted traffic through these load balancers are vulnerable.
     </p>
<h4 data-text="Patched images and vendor resources" id="patched-images-and-vendor-resources_2" tabindex="-1">Patched images and vendor resources</h4>
<p>We will provide links to patch information from each operating system
  vendor here as they become available, including the status for each CVE.
  Earlier versions of these public images don't contain these patches and don't
mitigate potential attacks:</p>
<ul>
<li>Project <code dir="ltr" translate="no">debian-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">debian-9-stretch-v20190618</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">centos-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">centos-6-v20190619</code></li>
<li><code dir="ltr" translate="no">centos-7-v20190619</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">cos-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">cos-dev-77-12293-0-0</code></li>
<li><code dir="ltr" translate="no">cos-beta-76-12239-21-0</code></li>
<li><code dir="ltr" translate="no">cos-stable-75-12105-77-0</code></li>
<li><code dir="ltr" translate="no">cos-73-11647-217-0</code></li>
<li><code dir="ltr" translate="no">cos-69-10895-277-0</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">coreos-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">coreos-alpha-2163-2-1-v20190617</code></li>
<li><code dir="ltr" translate="no">coreos-beta-2135-3-1-v20190617</code></li>
<li><code dir="ltr" translate="no">coreos-stable-2079-6-0-v20190617</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">rhel-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">rhel-6-v20190618</code></li>
<li><code dir="ltr" translate="no">rhel-7-v20190618</code></li>
<li><code dir="ltr" translate="no">rhel-8-v20190618</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">rhel-sap-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">rhel-7-4-sap-v20190618</code></li>
<li><code dir="ltr" translate="no">rhel-7-6-sap-v20190618</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">suse-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">sles-12-sp4-v20190617</code></li>
<li><code dir="ltr" translate="no">sles-15-v20190617</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">suse-sap-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">sles-12-sp1-sap-v20190617</code></li>
<li><code dir="ltr" translate="no">sles-12-sp2-sap-v20190617</code></li>
<li><code dir="ltr" translate="no">sles-12-sp3-sap-v20190617</code></li>
<li><code dir="ltr" translate="no">sles-12-sp4-sap-v20190617</code></li>
<li><code dir="ltr" translate="no">sles-15-sap-v20190617</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">ubuntu-cloud</code>:
      <ul>
<li><code dir="ltr" translate="no">ubuntu-1604-xenial-v20190617</code></li>
<li><code dir="ltr" translate="no">ubuntu-1804-bionic-v20190617</code></li>
<li><code dir="ltr" translate="no">ubuntu-1810-cosmic-v20190618</code></li>
<li><code dir="ltr" translate="no">ubuntu-1904-disco-v20190619</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1604-xenial-v20190618</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1804-bionic-v20190617</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1810-cosmic-v20190618</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1904-disco-v20190618</code></li>
</ul>
</li>
</ul>
</td>
<td>
  Medium
</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11477" target="mitre">CVE-2019-11477</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11478" target="mitre">CVE-2019-11478</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11479" target="mitre">CVE-2019-11479</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>Date published: 2019-05-14</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#20190514</id>
    <updated>2019-05-14T00:00:00+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#20190514"/>
    <content type="html"><![CDATA[<p><strong>last updated: 2019-05-20 T 17:00 PST</strong></p><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p>Intel has disclosed the following CVEs:</p>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-12126" target="mitre">CVE-2018-12126</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-12127" target="mitre">CVE-2018-12127</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2018-12130" target="mitre">CVE-2018-12130</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=2019-11091" target="mitre">CVE-2019-11091</a></li>
</ul>
<p>These CVEs are collectively referred to as Microarchitectural Data Sampling
      (MDS). These vulnerabilities potentially allow data to be exposed using the
      interaction of speculative execution with microarchitectural state.</p>
<h4 data-text="Compute Engine impact" id="20190514_impact" tabindex="-1">Compute Engine impact</h4>
<p><strong>The host infrastructure that runs Compute Engine isolates
      customer workloads from each other. Unless you are running untrusted code
        inside your VMs, no further action is required.</strong></p>
<p>For customers running untrusted code in their own multi-tenant services
      within Compute Engine virtual machines, refer to your Guest OS
      Vendor's recommended mitigation, which might include using Intel's
      microcode mitigation features. We have deployed guest pass-through access
        to the new flush functionality. The following is a summary of mitigation
        steps available for common guest images.</p>
<h4 data-text="Patched images and vendor resources" id="patched-images-and-vendor-resources_3" tabindex="-1">Patched images and vendor resources</h4>
<p>We will provide links to patch information from each operating system
      vendor here as they become available, including status for each CVE. Use
      these images to recreate VM instances. Earlier versions of these public
      images don't contain these patches and don't mitigate potential
      attacks:</p>
<ul>
<li>Project <code dir="ltr" translate="no">centos-cloud</code>: <a href="https://lists.centos.org/pipermail/centos-announce/2019-May/023309.html" target="centos">CESA-2019:1169</a>, <a href="https://lists.centos.org/pipermail/centos-announce/2019-May/023314.html" target="centos">CESA-2019:1168</a></li>
<ul>
<li><code dir="ltr" translate="no">centos-6-v20190515</code></li>
<li><code dir="ltr" translate="no">centos-7-v20190515</code></li>
</ul>
<li>Project <code dir="ltr" translate="no">coreos-cloud</code>: <a href="https://coreos.com/os/docs/latest/disabling-smt.html" target="coreos">MDS mitigations for CoreOS Container Linux</a></li>
<ul>
<li><code dir="ltr" translate="no">coreos-stable-2079-4-0-v20190515</code></li>
<li><code dir="ltr" translate="no">coreos-beta-2107-3-0-v20190515</code></li>
<li><code dir="ltr" translate="no">coreos-alpha-2135-1-0-v20190515</code></li>
</ul>
<li>Project <code dir="ltr" translate="no">cos-cloud</code></li>
<ul>
<li><code dir="ltr" translate="no">cos-69-10895-242-0</code></li>
<li><code dir="ltr" translate="no">cos-73-11647-182-0</code></li>
</ul>
<li>Project <code dir="ltr" translate="no">debian-cloud</code>:
      <a href="https://www.debian.org/security/2019/dsa-4444" target="debian">DSA-4444</a></li>
<ul>
<li><code dir="ltr" translate="no">debian-9-stretch-v20190514</code></li>
</ul>
<li>Project <code dir="ltr" translate="no">rhel-cloud</code>:
      <a href="https://access.redhat.com/security/vulnerabilities/mds" target="redhat">Red Hat MDS Knowledge Article</a></li>
<ul>
<li><code dir="ltr" translate="no">rhel-6-v20190515</code></li>
<li><code dir="ltr" translate="no">rhel-7-v20190517</code></li>
<li><code dir="ltr" translate="no">rhel-8-v20190515</code></li>
</ul>
<li>Project <code dir="ltr" translate="no">rhel-sap-cloud</code>:
      <a href="https://access.redhat.com/security/vulnerabilities/mds" target="redhat">Red Hat MDS Knowledge Article</a></li>
<ul>
<li><code dir="ltr" translate="no">rhel-7-4-sap-v20190515</code></li>
<li><code dir="ltr" translate="no">rhel-7-6-sap-v20190517</code></li>
</ul>
<li>Project <code dir="ltr" translate="no">suse-cloud</code>: <a href="https://www.suse.com/support/kb/doc/?id=7023736" target="suse">
      SUSE MDS KB</a></li>
<ul>
<li><code dir="ltr" translate="no">sles-12-sp4-v20190520</code></li>
<li><code dir="ltr" translate="no">sles-15-v20190520</code></li>
</ul>
<li>Project <code dir="ltr" translate="no">suse-sap-cloud</code></li>
<ul>
<li><code dir="ltr" translate="no">sles-12-sp4-sap-v20190520</code></li>
<li><code dir="ltr" translate="no">sles-15-sap-v20190520</code></li>
</ul>
<li>Project <code dir="ltr" translate="no">ubuntu-os-cloud</code>:
      <a href="https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/MDS" target="ubuntu">Ubuntu MDS Wiki</a></li>
<ul>
<li><code dir="ltr" translate="no">ubuntu-1404-trusty-v20190514</code></li>
<li><code dir="ltr" translate="no">ubuntu-1604-xenial-v20190514</code></li>
<li><code dir="ltr" translate="no">ubuntu-1804-bionic-v20190514</code></li>
<li><code dir="ltr" translate="no">ubuntu-1810-cosmic-v20190514</code></li>
<li><code dir="ltr" translate="no">ubuntu-1904-disco-v20190514</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1604-xenial-v20190514</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1804-bionic-v20190514</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1810-cosmic-v20190514</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1904-disco-v20190514</code></li>
</ul>
<li>Projects <code dir="ltr" translate="no">windows-cloud</code> and
      <code dir="ltr" translate="no">windows-sql-cloud</code>: <a href="https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/ADV190013" target="msrc">Microsoft ADV190013</a></li>
<ul>
<li>All Windows Server and SQL Server public images with version number <code dir="ltr" translate="no">v20190514</code>.</li>
</ul>
<li>Project <code dir="ltr" translate="no">gce-uefi-images</code></li>
<ul>
<li><code dir="ltr" translate="no">centos-7-v20190515</code></li>
<li><code dir="ltr" translate="no">cos-69-10895-242-0</code></li>
<li><code dir="ltr" translate="no">cos-73-11647-182-0</code></li>
<li><code dir="ltr" translate="no">rhel-7-v20190517</code></li>
<li><code dir="ltr" translate="no">ubuntu-1804-bionic-v20190514</code></li>
<li>All Windows Server public images with version number <code dir="ltr" translate="no">v20190514</code>.</li>
</ul>
</ul>
<h4 data-text="Container-Optimized OS" id="container-optimized-os" tabindex="-1">Container-Optimized OS</h4>
<p>If you are using Container Optimized OS (COS) as your Guest OS and you are
      running untrusted, multi-tenant workloads in your virtual machine, we
      recommend that you:</p>
<ol>
<li>Disable Hyper-Threading by setting <code dir="ltr" translate="no">nosmt</code> on the kernel
          command-line.<br/>
<p>On existing COS VMs, you can modify the <code dir="ltr" translate="no">grub.cfg</code> as
            follows to set the <code dir="ltr" translate="no">nosmt</code> option and then reboot the system:</p>
<div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no"># Run as root:
dir="$(mktemp -d)"
mount /dev/sda12 "${dir}"
sed -i -e "s|cros_efi|cros_efi nosmt|g" "${dir}/efi/boot/grub.cfg"
umount "${dir}"
rmdir "${dir}"

reboot</pre></devsite-code>
<p>For convenience, you can run the script below to achieve the same
           result as running the commands earlier. We recommend making this script
           part of your cloud-config, startup scripts or instance templates, to
           ensure that new VMs use this new parameter. An example cloud-config
           that runs this script is below.
         </p>
<p class="warning"><strong>Warning:</strong> This command will result in
         an immediate reboot of the instance when run for the first time.
         Subsequent runs of the command on an instance with Hyper-Threading
         already disabled will have no effect.</p>
<div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no">
# Run as root
/bin/bash &lt;(curl -s https://storage.googleapis.com/cos-tools/scripts/disable_smt.sh)
</pre></devsite-code>
<p>To include this as part of your cloud-config:</p>
<div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no">
#cloud-config

bootcmd:
- /bin/bash -c "/bin/bash &lt;(curl -s https://storage.googleapis.com/cos-tools/scripts/disable_smt.sh)"
</pre></devsite-code>
<p>To confirm if Hyper-Threading is disabled on your instance,
         look at the output of
         <code dir="ltr" translate="no">/sys/devices/system/cpu/smt/active</code> and
         <code dir="ltr" translate="no">/sys/devices/system/cpu/smt/control</code> files. If it returns
           <code dir="ltr" translate="no">0</code> for <code dir="ltr" translate="no">active</code> and <code dir="ltr" translate="no">off</code> for
         <code dir="ltr" translate="no">control</code>, Hyper-Threading is disabled:</p>
<div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no">
cat /sys/devices/system/cpu/smt/active
cat /sys/devices/system/cpu/smt/control
</pre></devsite-code>
<p class="note"><strong>Note:</strong> If you have enabled UEFI Secure
        Boot on your instance, you will need to re-create your instance with
        UEFI Secure Boot disabled, run the above command with UEFI Secure Boot
        disabled, and then enable UEFI Secure Boot on your new instance.</p>
</li>
<li>Use new version of COS image
        <br/>
<p>In addition to disabling Hyper-Threading as described above, you should
        also <a href="https://docs.cloud.google.com/compute/docs/instances/create-start-instance#publicimage">re-create
        your instances</a> with the updated images listed above or newer versions
        (when available) of Container-Optimized OS images to get fully protected from the
        vulnerability.</p>
</li>
</ol>
</td>
<td>
  Medium
</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12126" target="mitre">CVE-2018-12126</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12127" target="mitre">CVE-2018-12127</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-12130" target="mitre">CVE-2018-12130</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11091" target="mitre">CVE-2019-11091</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>Date published: 2018-08-14</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#20180814</id>
    <updated>2018-08-14T00:00:00+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#20180814"/>
    <content type="html"><![CDATA[<p><strong>last updated: 2018-08-20 T 17:00 PST</strong></p><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<h4 data-text="Description" id="20180814_description" tabindex="-1">Description</h4>
<p><a href="https://www.intel.com/content/www/us/en/architecture-and-technology/l1tf.html">Intel has disclosed</a> the following CVEs:</p>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3615" target="mitre">CVE-2018-3615</a> (for <a href="https://en.wikipedia.org/wiki/Software_Guard_Extensions">SGX</a>)</li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3620" target="mitre">CVE-2018-3620</a> (for operating systems and <a href="https://en.wikipedia.org/wiki/Hyper-Threading">SMT</a>)</li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3646" target="mitre">CVE-2018-3646</a> (for virtualization)</li>
</ul>
<p>These CVEs are collectively referred to as "L1 Terminal Fault (L1TF)".</p>
<p>These L1TF vulnerabilities exploit speculative execution by
      attacking the configuration of processor-level data structures.
      "L1" refers to the Level-1 Data cache (L1D), a small on-core
      resource used to accelerate memory access.</p>
<p>Read the
      <a href="https://cloud.google.com/blog/products/gcp/protecting-against-the-new-l1tf-speculative-vulnerabilities">Google Cloud blog post</a>
      for more details on these
      vulnerabilities and Compute Engine's mitigations.</p>
<h4 data-text="Compute Engine impact" id="20180814_impact" tabindex="-1">Compute Engine impact</h4>
<p>The host infrastructure that runs Compute Engine and isolates customer
      workloads from each other is protected against known attacks.</p>
<p>Compute Engine customers are encouraged to update their images to
      prevent the possibility of indirect exploitation within their guest
      environments. This is particularly important for customers running
      their own multi-tenant services on Compute Engine virtual machines.</p>
<p>Compute Engine customers can update the guest operating
      systems on their instances using one of the following options:</p>
<ul>
<li>Use patched public images to
        <a href="https://docs.cloud.google.com/compute/docs/instances/create-start-instance#publicimage">recreate existing VM instances</a>.</li>
<li>On existing instances, install patches provided by the operating
        system vendor and reboot the patched instances.</li>
</ul>
<h4 data-text="Patched images and vendor resources" id="20180814_patched_images" tabindex="-1">Patched images and vendor resources</h4>
<p>We will provide links to patch information from each operating
      system vendor here as they become available, including status for both
      CVEs. Use these images to recreate VM instances. Earlier versions of
      these public images don't contain these patches and don't mitigate
      potential attacks:</p>
<ul>
<li>Project <code dir="ltr" translate="no">centos-cloud</code>:
          <ul>
<li><code dir="ltr" translate="no">centos-7-v20180815</code></li>
<li><code dir="ltr" translate="no">centos-6-v20180815</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">coreos-cloud</code>:
          <ul>
<li><code dir="ltr" translate="no">coreos-stable-1800-7-0-v20180816</code></li>
<li><code dir="ltr" translate="no">coreos-beta-1855-2-0-v20180816</code></li>
<li><code dir="ltr" translate="no">coreos-alpha-1871-0-0-v20180816</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">cos-cloud</code>:
          <ul>
<li><code dir="ltr" translate="no">cos-stable-66-10452-110-0</code></li>
<li><code dir="ltr" translate="no">cos-stable-67-10575-66-0</code></li>
<li><code dir="ltr" translate="no">cos-beta-68-10718-81-0</code></li>
<li><code dir="ltr" translate="no">cos-dev-69-10895-23-0</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">debian-cloud</code>:
          <ul>
<li><code dir="ltr" translate="no">debian-9-stretch-v20180820</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">rhel-cloud</code>:
          <ul>
<li><code dir="ltr" translate="no">rhel-7-v20180814</code></li>
<li><code dir="ltr" translate="no">rhel-6-v20180814</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">rhel-sap-cloud</code>:
          <ul>
<li><code dir="ltr" translate="no">rhel-7-sap-apps-v20180814</code></li>
<li><code dir="ltr" translate="no">rhel-7-sap-hana-v20180814</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">suse-cloud</code>:
          <ul>
<li><code dir="ltr" translate="no">sles-15-v20180816</code></li>
<li><code dir="ltr" translate="no">sles-12-sp3-v20180814</code></li>
<li><code dir="ltr" translate="no">sles-11-sp4-v20180816</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">suse-sap-cloud</code>:
          <ul>
<li><code dir="ltr" translate="no">sles-15-sap-v20180816</code></li>
<li><code dir="ltr" translate="no">sles-12-sp3-sap-v20180814</code></li>
<li><code dir="ltr" translate="no">sles-12-sp2-sap-v20180816</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">ubuntu-os-cloud</code>:
          <ul>
<li><code dir="ltr" translate="no">ubuntu-1804-bionic-v20180814</code></li>
<li><code dir="ltr" translate="no">ubuntu-1604-xenial-v20180814</code></li>
<li><code dir="ltr" translate="no">ubuntu-1404-trusty-v20180814</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1804-bionic-v20180814</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1604-xenial-v20180814</code></li>
</ul>
</li>
<li>Projects <code dir="ltr" translate="no">windows-cloud</code> <code dir="ltr" translate="no">gce-uefi-images</code> and
          <code dir="ltr" translate="no">windows-sql-cloud</code>:
          <ul>
<li> All Windows Server and SQL Server
            <a href="https://docs.cloud.google.com/compute/docs/images#os-compute-support">public images</a>
            with version number <code dir="ltr" translate="no">-v201800814</code> and later include
              patches.</li>
</ul>
</li>
</ul>
</td>
<td>High</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3615" target="mitre">CVE-2018-3615</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3620" target="mitre">CVE-2018-3620</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3646" target="mitre">CVE-2018-3646</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>Date published: 2018-08-06</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#20180806</id>
    <updated>2018-08-06T00:00:00+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#20180806"/>
    <content type="html"><![CDATA[<p><strong>last updated: 2018-09-05 T 17:00 PST</strong></p><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<h4 data-text="2018-09-05 Update" id="20180905_update" tabindex="-1">2018-09-05 Update</h4>
<p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5391">CVE-2018-5391</a>
      was disclosed on 2018-08-14 by US-CERT. As with
      <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5390" target="mitre">CVE-2018-5390</a>,
      this is a kernel-level networking vulnerability that increases the
      effectiveness of denial of service (DoS) attacks against vulnerable
      systems. The main difference is that CVE-2018-5391 is exploitable over
      IP connections. We updated this bulletin to cover both vulnerabilities.
      </p>
<h4 data-text="Description" id="20180806_description" tabindex="-1">Description</h4>
<p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5390" target="mitre">CVE-2018-5390</a> ("SegmentSmack") describes a kernel-level networking
      vulnerability that increases the effectiveness of denial of service
      (DoS) attacks against vulnerable systems over TCP connections.</p>
<p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5391" target="mitre">CVE-2018-5391</a>
      ("FragmentSmack") describes a kernel-level networking vulnerability
      that increases the effectiveness of denial of service (DoS) attacks
      against vulnerable systems over IP connections.</p>
<h4 data-text="Compute Engine impact" id="20180806_impact" tabindex="-1">Compute Engine impact</h4>
<p>The host infrastructure that runs Compute Engine VMs is not at risk.
      The network infrastructure that handles traffic to and from Compute Engine
      VMs is protected against this vulnerability. Compute Engine VMs that only
      send/receive untrusted network traffic using
      <a href="https://docs.cloud.google.com/load-balancing/docs/https">HTTP(S)</a>,
      <a href="https://docs.cloud.google.com/load-balancing/docs/ssl">SSL</a>, or
      <a href="https://docs.cloud.google.com/load-balancing/docs/tcp">TCP Load Balancers</a>
      are protected against this vulnerability.</p>
<p>Compute Engine VMs running unpatched operating systems that
      send/receive untrusted network traffic directly, or using
      <a href="https://docs.cloud.google.com/load-balancing/docs/network">Network Load Balancers</a>,
      are vulnerable to this DoS attack.</p>
<p>Consider updating your VM instances as soon as patches are available
      for their operating systems.</p>
<p>Compute Engine customers can update the guest operating systems on
      their instances using one of the following options:</p>
<ul>
<li>Use patched public images to
        <a href="https://docs.cloud.google.com/compute/docs/instances/create-start-instance#publicimage">recreate existing VM instances</a>.
        See the list of patched public images below.</li>
<li>On existing instances, install patches provided by the operating
        system vendor and reboot the patched instances.</li>
</ul>
<h4 data-text="Patched images and vendor resources" id="20180806_patched_images" tabindex="-1">Patched images and vendor resources</h4>
<p>We will provide links to patch information from each operating system
      vendor here as they become available.</p>
<ul>
<li>Project <code dir="ltr" translate="no">centos-cloud</code> (CVE-2018-5390 only):
          <ul>
<li><code dir="ltr" translate="no">centos-7-v20180815</code></li>
<li><code dir="ltr" translate="no">centos-6-v20180815</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">coreos-cloud</code> (CVE-2018-5390 and CVE-2018-5391):
          <ul>
<li><code dir="ltr" translate="no">coreos-stable-1800-7-0-v20180816</code></li>
<li><code dir="ltr" translate="no">coreos-beta-1855-2-0-v20180816</code></li>
<li><code dir="ltr" translate="no">coreos-alpha-1871-0-0-v20180816</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">cos-cloud</code> (CVE-2018-5390 and CVE-2018-5391):
          <ul>
<li><code dir="ltr" translate="no">cos-stable-65-10323-98-0</code></li>
<li><code dir="ltr" translate="no">cos-stable-66-10452-109-0</code></li>
<li><code dir="ltr" translate="no">cos-stable-67-10575-65-0</code></li>
<li><code dir="ltr" translate="no">cos-beta-68-10718-76-0</code></li>
<li><code dir="ltr" translate="no">cos-dev-69-10895-16-0</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">debian-cloud</code> (CVE-2018-5390 and CVE-2018-5391):
          <ul>
<li><code dir="ltr" translate="no">debian-9-stretch-v20180814</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">rhel-cloud</code> (CVE-2018-5390 only):
          <ul>
<li><code dir="ltr" translate="no">rhel-7-v20180814</code></li>
<li><code dir="ltr" translate="no">rhel-6-v20180814</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">suse-cloud</code> (CVE-2018-5390 and CVE-2018-5391):
          <ul>
<li><code dir="ltr" translate="no">sles-15-v20180816</code></li>
<li><code dir="ltr" translate="no">sles-12-sp3-v20180814</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">suse-sap-cloud</code> (CVE-2018-5390 and CVE-2018-5391):
          <ul>
<li><code dir="ltr" translate="no">sles-15-sap-v20180816</code></li>
<li><code dir="ltr" translate="no">sles-12-sp3-sap-v20180814</code></li>
<li><code dir="ltr" translate="no">sles-12-sp2-sap-v20180816</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">ubuntu-os-cloud</code> (CVE-2018-5390 and CVE-2018-5391):
          <ul>
<li><code dir="ltr" translate="no">ubuntu-1804-bionic-v20180814</code></li>
<li><code dir="ltr" translate="no">ubuntu-1604-xenial-v20180814</code></li>
<li><code dir="ltr" translate="no">ubuntu-1404-trusty-v20180814</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1804-bionic-v20180814</code></li>
<li><code dir="ltr" translate="no">ubuntu-minimal-1604-xenial-v20180814</code></li>
</ul>
</li>
</ul>
</td>
<td>High</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5390" target="mitre">CVE-2018-5390</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-5391" target="mitre">CVE-2018-5391</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>Date published: 2018-01-03</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#20180103</id>
    <updated>2018-01-03T00:00:00+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#20180103"/>
    <content type="html"><![CDATA[<p><strong>last updated: 2018-05-21 T 15:00 PST</strong></p><table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<h4 data-text="2018-05-21 Update" id="20180521_update" tabindex="-1">2018-05-21 Update</h4>
<p><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3640" target="mitre">CVE-2018-3640</a>
      and <a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3639" target="mitre">CVE-2018-3639</a>,
      Variants 3a and 4 respectively, were <a href="https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00115.html" target="intel">disclosed by Intel</a>. As with the first
      three variants of Spectre and Meltdown, the infrastructure that runs
      Compute Engine VM instances is protected and customer VM
      instances are isolated and protected from one another. Additionally,
      Compute Engine plans to deploy Intel's microcode patches to
      our infrastructure, which will allow customers who run untrusted
      or multi-tenant workloads within a single VM instance to enable additional
      intra-VM mitigations when those mitigations are provided by operating
      system vendors and providers. Compute Engine will deploy the
      microcode patches once Intel has certified them and after
      Compute Engine has tested and qualified the patches for our
      production environment. We will provide more detailed timelines and
      updates on this page as they become available.</p>
<h4 data-text="Description" id="20180103_description" tabindex="-1">Description</h4>
<p>These CVEs are variants of a new class of attack that exploit
      the speculative execution technology available in many processors.
      This class of attack can allow for unauthorized read-only access
      to memory data under various circumstances.</p>
<p>Compute Engine used VM Live Migration technology to perform host
      system and hypervisor updates with no user impact, no forced maintenance
      windows, and no mass reboots required. However, all guest operating
      systems and versions must be patched to protect against this new class
      of attack regardless of where those systems run.</p>
<p>Read the
      <a href="https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html" target="google">Project Zero blog post</a>
      for complete technical details on this attack method. Read the
      <a href="https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html" target="google">Google Security blog post</a>
      for complete details on Google's mitigations including all
      product-specific information.</p>
<h4 data-text="Compute Engine impact" id="20180103_impact" tabindex="-1">Compute Engine impact</h4>
<p>The infrastructure that runs Compute Engine and isolates
      customer VM instances from each other is protected against known attacks.
      Our mitigations prevent unauthorized access to our host systems from
      applications running inside VM instances. These mitigations also
      prevent unauthorized access between VM instances running on the same
      host system.</p>
<p>To prevent unauthorized access within your virtual machine instances,
      you must update the guest operating systems on those instances using one
      of the following options:</p>
<ul>
<li>Use patched public images to
        <a href="https://docs.cloud.google.com/compute/docs/instances/create-start-instance#publicimage">recreate your existing VM instances</a>.
        See the list of patched public images below.</li>
<li>On your existing instances, install patches provided by the
        operating system vendor for your distribution and reboot the
        patched instances. See the links to patch information from each
        operating system vendor below.</li>
</ul>
<h4 data-text="Patched images and vendor resources" id="20180103_patched_images" tabindex="-1">Patched images and vendor resources</h4>
<p class="note">
<strong>Note:</strong> Patched images might not include fixes for all
        of the CVEs listed in this security bulletin notice. Additionally,
        different images might include different methods for preventing
        these types of attacks. Check with your operating
        system vendor to confirm which CVEs they address in their patches and
        what prevention methods they use.
      </p>
<ul>
<li>Project <code dir="ltr" translate="no">cos-cloud</code>: Includes patches that prevent
            Variant 2
            (<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5715" target="mitre">CVE-2017-5715</a>)
            and Variant 3
            (<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5754" target="mitre">CVE-2017-5754</a>)
            attacks. Google used
            <a href="https://support.google.com/faqs/answer/7625886" target="google">Retpoline</a>
            in these images to mitigate Variant 2 attacks.
          <ul>
<li><code dir="ltr" translate="no">cos-stable-63-10032-71-0</code> or image family <code dir="ltr" translate="no">cos-stable</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">centos-cloud</code>:
          <a href="https://lwn.net/Alerts/CentOS/" target="lwn">CentOS patch information</a>
<ul>
<li><code dir="ltr" translate="no">centos-7-v20180104</code> or image family <code dir="ltr" translate="no">centos-7</code></li>
<li><code dir="ltr" translate="no">centos-6-v20180104</code> or image family <code dir="ltr" translate="no">centos-6</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">coreos-cloud</code>:
          <a href="https://coreos.com/blog/container-linux-meltdown-patch" target="coreos">CoreOS patch information</a>
<ul>
<li><code dir="ltr" translate="no">coreos-stable-1576-5-0-v20180105</code> or image family <code dir="ltr" translate="no">coreos-stable</code></li>
<li><code dir="ltr" translate="no">coreos-beta-1632-1-0-v20180105</code> or image family <code dir="ltr" translate="no">coreos-beta</code></li>
<li><code dir="ltr" translate="no">coreos-alpha-1649-0-0-v20180105</code> or image family <code dir="ltr" translate="no">coreos-alpha</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">debian-cloud</code>:
          <a href="https://www.debian.org/security/#DSAS" target="debian">Debian patch information</a>
<ul>
<li><code dir="ltr" translate="no">debian-9-stretch-v20180105</code> or image family <code dir="ltr" translate="no">debian-9</code></li>
<li><code dir="ltr" translate="no">debian-8-jessie-v20180109</code> or image family <code dir="ltr" translate="no">debian-8</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">rhel-cloud</code>:
          <a href="https://access.redhat.com/security/vulnerabilities/speculativeexecution" target="redhat">RHEL patch information</a>
<ul>
<li><code dir="ltr" translate="no">rhel-7-v20180104</code> or image family <code dir="ltr" translate="no">rhel-7</code></li>
<li><code dir="ltr" translate="no">rhel-6-v20180104</code> or image family <code dir="ltr" translate="no">rhel-6</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">suse-cloud</code>:
          <a href="https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/" target="suse">SUSE patch information</a>
<ul>
<li><code dir="ltr" translate="no">sles-12-sp3-v20180104</code> or image family <code dir="ltr" translate="no">sles-12</code></li>
<li><code dir="ltr" translate="no">sles-11-sp4-v20180104</code> or image family <code dir="ltr" translate="no">sles-11</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">suse-sap-cloud</code>:
          <a href="https://www.suse.com/c/suse-addresses-meltdown-spectre-vulnerabilities/" target="suse">SUSE patch information</a>
<ul>
<li><code dir="ltr" translate="no">sles-12-sp3-sap-v20180104</code> or image family <code dir="ltr" translate="no">sles-12-sp3-sap</code></li>
<li><code dir="ltr" translate="no">sles-12-sp2-sap-v20180104</code> or image family <code dir="ltr" translate="no">sles-12-sp2-sap</code></li>
</ul>
</li>
<li>Project <code dir="ltr" translate="no">ubuntu-os-cloud</code>:
          <a href="https://insights.ubuntu.com/2018/01/04/ubuntu-updates-for-the-meltdown-spectre-vulnerabilities/" target="ubuntu">Ubuntu patch information</a>
<ul>
<li><code dir="ltr" translate="no">ubuntu-1710-artful-v20180109</code> or image family <code dir="ltr" translate="no">ubuntu-1710</code></li>
<li><code dir="ltr" translate="no">ubuntu-1604-xenial-v20180109</code> or image family <code dir="ltr" translate="no">ubuntu-1604-lts</code></li>
<li><code dir="ltr" translate="no">ubuntu-1404-trusty-v20180110</code> or image family <code dir="ltr" translate="no">ubuntu-1404-lts</code></li>
</ul>
</li>
<li>Projects <code dir="ltr" translate="no">windows-cloud</code> and
          <code dir="ltr" translate="no">windows-sql-cloud</code>:
          <ul>
<li> All Windows Server and SQL Server
            <a href="https://docs.cloud.google.com/compute/docs/images#os-compute-support">public images</a>
            with version number <code dir="ltr" translate="no">-v20180109</code> and later include
            patches. However, you must follow the recommended actions
            provided by Microsoft in the
            <a href="https://support.microsoft.com/en-gb/help/4072698/windows-server-guidance-to-protect-against-the-speculative-execution" target="ms">Windows Server guidance</a>
            support bulletin to enable and verify these mitigations on both
            your existing instances and newly-created instances.</li>
</ul>
</li>
</ul>
<p>Use these images to
      <a href="https://docs.cloud.google.com/compute/docs/instances/create-start-instance#publicimage">recreate your VM instances</a>.
      Earlier versions of these public images don't contain these patches and
      don't mitigate potential attacks.</p>
<h4 data-text="Patches from hardware vendors" id="20180103_hardware_patches" tabindex="-1">Patches from hardware vendors</h4>
<p>NVIDIA provides patched drivers to mitigate potential attacks against
      systems that have NVIDIA® driver software installed. To learn
      which driver versions are patched, read the
      <a href="http://nvidia.custhelp.com/app/answers/detail/a_id/4611" target="nvidia">NVIDIA GPU Display Driver Security Updates</a>
      security bulletin from NVIDIA.</p>
<h4 data-text="Revision history:" id="20180103_history" tabindex="-1">Revision history:</h4>
<ul>
<li>2018-05-21 T 14:00 PST: Added information about 2 new variants
      disclosed on May 21, 2018.</li>
<li>2018-01-10 T 15:00 PST: Added information about patched Windows
      Server and SQL Server public images.</li>
<li>2018-01-10 T 10:15 PST: Added several Ubuntu images to the list of
      patched public images.</li>
<li>2018-01-10 T 09:50 PST: Added guidance for patches from hardware
      vendors.</li>
<li>2018-01-03 to 2018-01-09: Made several revisions to the list of
      patched public images.</li>
</ul>
</td>
<td>High</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5753" target="mitre">CVE-2017-5753</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5715" target="mitre">CVE-2017-5715</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5754" target="mitre">CVE-2017-5754</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3640" target="mitre">CVE-2018-3640</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3639" target="mitre">CVE-2018-3639</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>

  <entry>
    <title>Date published: 2017-10-02</title>
    <id>tag:google.com,2016:compute-engine-security-bulletins#20171002</id>
    <updated>2017-10-02T00:00:00+00:00</updated>
    <link rel="alternate" href="https://docs.cloud.google.com/compute/docs/security-bulletins#20171002"/>
    <content type="html"><![CDATA[<table class="fixed">
<thead>
<tr>
<th width="70%">Description</th>
<th>Severity</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>
<p><a href="http://www.thekelleys.org.uk/dnsmasq/doc.html" target="thekelleys">Dnsmasq</a>
        provides functionality for serving DNS, DHCP, router
        advertisements, and network boot. This software is commonly installed
        in systems as varied as desktop Linux distributions (like Ubuntu), home
        routers, and IoT devices. Dnsmasq is widely used both on the open
        Internet and internally in private networks.</p>
<p>Google discovered seven distinct issues over the course of our regular
        internal security assessments. After we determined the severity of these
        issues, we worked to investigate their impact and exploitability and then
        produced internal proofs of concept for each of them. We also worked
        with the maintainer of Dnsmasq, Simon Kelly, to produce appropriate
        patches and mitigate the issue.</p>
<p>During our review, the team found three potential remote code
      executions, one information leak, and three denial of service
      vulnerabilities affecting the latest version at the project git server as
      of September 5th 2017.</p>
<p>These patches are upstreamed and are committed to the
      <a href="http://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=summary" target="thekelleys">
      project's Git repository</a>.</p>
<h4 data-text="Compute Engine impact" id="compute-engine-impact_2" tabindex="-1">Compute Engine impact</h4>
<p>By default, Dnsmasq is only installed in images that use
      <a href="https://wikipedia.org/wiki/NetworkManager" target="wikipedia">NetworkManager</a>
      and is inactive by default. The following Compute Engine public
      images have Dnsmasq installed:</p>
<ul>
<li>Ubuntu 16.04, 16.10, 17.04</li>
<li>CentOS 7</li>
<li>RHEL 7</li>
</ul>
<p>However, other images might have Dnsmasq installed as a
      dependency for other packages. We recommend that you update your
      Debian, Ubuntu, CentOS, RHEL, SLES, and OpenSuse instances to use the
      latest operating system image.
      CoreOS and Container-Optimized OS are not affected. Windows images are
      also unaffected.</p>
<p>For instances running Debian and Ubuntu, you can perform an update by
      running the following commands in your instance:</p>
<div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no">sudo apt-get -y update</pre></devsite-code>
<div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no">sudo apt-get -y dist-upgrade</pre></devsite-code>
<p>For Red Hat Enterprise Linux and CentOS instances, run:</p>
<div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no">sudo yum -y upgrade</pre></devsite-code>
<p>For SLES and OpenSUSE images, run:</p>
<div></div><devsite-code><pre dir="ltr" is-upgraded="" translate="no">sudo zypper up</pre></devsite-code>
<p>As an alternative to running the manual update commands, you can
      <a href="https://docs.cloud.google.com/compute/docs/instances/create-start-instance#publicimage">
      recreate VM instances using the image families</a>
      of the respective operating system.</p>
</td>
<td>High</td>
<td>
<ul>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14491" target="mitre">CVE-2017-14491</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14492" target="mitre">CVE-2017-14492</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14493" target="mitre">CVE-2017-14493</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14494" target="mitre">CVE-2017-14494</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14495" target="mitre">CVE-2017-14495</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-14496" target="mitre">CVE-2017-14496</a></li>
<li><a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13704" target="mitre">CVE-2017-13704</a></li>
</ul>
</td>
</tr>
</tbody>
</table>]]>
    </content>
  </entry>


</feed>
