本文列出 Google Kubernetes Engine (GKE) 1.34 子版本的修補程式版本異動。
這些變更記錄是特定 GKE 系統元件更新的補充資訊。如要瞭解 GKE 的功能、異動和安全性問題,請參閱下列文件:
1.34.11-gke.1044000
以下各節說明這個修補程式版本與上一個修補程式版本 1.34.10-gke.1328000 的差異。如要瞭解上游 Kubernetes 的變更,請參閱 Kubernetes v1.34.11 變更記錄。
元件更新
以下各節說明這個修補程式版本中,特定 GKE 系統元件的更新內容。
advanceddatapath
將 advanceddatapath 元件從 34.8.43 版更新至 34.8.44 版。
- 安全性修正:
- 更新
golang.org/x/net,解決 GO-2026-5942 問題。 - 已更新
golang.org/x/text,解決 GO-2026-5970 問題。 - 更新 Debian Bookworm 和 Bullseye 基本映像檔,加入最新安全性修補程式。
- 更新
kube-addon-manager
將 kube-addon-manager 元件從 31.0.21 版更新至 31.0.22 版。
- 其他:
- 已將
gke-distroless/bash容器映像檔更新為gke_distroless_20260815.00_p0版。
- 已將
networkpolicy-antrea
將 networkpolicy-antrea 元件從 0.5.9 版更新至 0.5.10 版。
- 其他:
- 已將「
cluster-proportional-autoscaler」更新為 v1.10.2-gke.54。
- 已將「
networkpolicy-calico
將 networkpolicy-calico 元件從 4.34.9 版更新至 4.34.10 版。
- 安全性修正:
- 將 Go 建構版本更新至 1.25.12,修正
calico/node中的 CVE-2026-39822。 - 已在
calico/node中將golang.org/x/crypto更新至 v0.52.0,以修正安全漏洞。
- 將 Go 建構版本更新至 1.25.12,修正
tpu-device-plugin
將 tpu-device-plugin 元件從 1.34.17-gke.6 版更新至 1.34.17-gke.7 版。
- 安全性修正:
- 已將
google.golang.org/grpc更新至 v1.82.1,以解決 GO-2026-6061。
- 已將
1.34.10-gke.1328000
與上一個修補程式版本 1.34.10-gke.1236000 相比,這個修補程式版本有以下變更。如要瞭解上游 Kubernetes 的變更,請參閱 Kubernetes v1.34.10 變更記錄。
元件更新
以下各節說明這個修補程式版本中,特定 GKE 系統元件的更新內容。
accelerator-operator
將 accelerator-operator 元件從 1.34.10 版更新至 1.34.11 版。
- 其他:
- 將 accelerator-operator 容器映像檔更新至 v1.34.5-gke.13 版。
customer-logs-exporter
將 customer-logs-exporter 元件從 1.34.0-gke.8 版更新至 1.34.0-gke.9 版。
- 其他:
- 更新元件使用的
bash基本映像檔。
- 更新元件使用的
gcsfusecsi
gcsfusecsi 元件已從 1.34.58 版更新至 1.34.59 版。
- 其他:
- 將 Go 執行階段更新至 1.25.14 版,並更新 Google Cloud Storage Fuse CSI 驅動程式、node-driver-registrar、sidecar mounter、webhook 和中繼資料預先擷取器的基本映像檔。
osimage
osimage 元件已從 1.34.181 版更新為 1.34.197 版。
- 功能:
- 在 x86_64 架構上啟用 CONFIG_UDMABUF。
- 新增 VM 限制的 bpf-lsm-policy。
- Linux 核心已更新至 COS-6.12.94。
- Docker 已更新至 v27.5.1。
- 已將 containerd 更新至 v2.1.9。
- 在 Linux 核心中為 ARM64 啟用
CONFIG_MEMORY_FAILURE,以改善執行 CUDA 工作負載時的記憶體錯誤處理機制。
- 錯誤修正:
- 套用核心修補程式,縮短 bcache 垃圾回收的休眠間隔,避免潛在的 I/O 停滯。
- 解決影響 XFS 檔案系統使用者的重大問題。
- 更新
protected_stateful_partition的 udev 規則設定。 - 已將 curl 升級至 8.21.0 版。
- 已將
google-guest-agent外掛程式的安裝路徑變更為/var/lib/google/guest-agent。
- 安全性修正:
- 修正 Linux 核心中的 CVE-2026-68329。
- 修正 Linux 核心中的 CVE-2026-64380。
- 修正 Linux 核心中的 CVE-2026-64561。
- 修正 Linux 核心中的 CVE-2026-64562。
- 修正 Linux 核心中的 CVE-2026-64567。
- 修正 Linux 核心中的 CVE-2026-64572。
- 修正 Linux 核心中的 CVE-2026-64576。
- 修正 Linux 核心中的 CVE-2026-64579。
- 修正 Linux 核心中的 CVE-2026-64580。
- 修正 Linux 核心中的 CVE-2026-64590。
- 修正 Linux 核心中的 CVE-2026-64593。
- 修正 Linux 核心中的 CVE-2026-64597。
- 修正 Linux 核心中的 CVE-2026-64598。
- 修正 Linux 核心中的 CVE-2026-64604。
- 修正 Linux 核心中的 CVE-2026-68092。
- 修正 Linux 核心中的 CVE-2026-68119。
- 修正 Linux 核心中的 CVE-2026-68136。
- 修正 Linux 核心中的 CVE-2026-68142。
- 修正 Linux 核心中的 CVE-2026-68145。
- 修正 Linux 核心中的 CVE-2026-68146。
- 修正 Linux 核心中的 CVE-2026-68147。
- 修正 Linux 核心中的 CVE-2026-68149。
- 修正 Linux 核心中的 CVE-2026-68184。
- 修正 Linux 核心中的 CVE-2026-68186。
- 修正 Linux 核心中的 CVE-2026-68187。
- 修正 Linux 核心中的 CVE-2026-68284。
- 修正 Linux 核心中的 CVE-2026-68338。
- 修正 Linux 核心中的 CVE-2026-68388。
- 修正 Linux 核心中的 CVE-2026-68396。
- 修正 Linux 核心中的 CVE-2026-68398。
- 修正 Linux 核心中的 CVE-2026-68422。
- 修正 Linux 核心中的 CVE-2026-68425。
- 修正 Linux 核心中的 CVE-2026-68428。
- 修正 Linux 核心中的 CVE-2026-68432。
- 修正 Linux 核心中的 CVE-2026-68442。
- 修正 Linux 核心中的 CVE-2026-68450。
- 修正 app-editors/vim 和 app-editors/vim-core 中的 CVE-2026-35177。
- 修正 dev-go/crypto 中的 CVE-2026-39827、CVE-2026-39828、CVE-2026-39829、CVE-2026-39830、CVE-2026-39831、CVE-2026-39832、CVE-2026-39833、CVE-2026-39834、CVE-2026-39835、CVE-2026-42508、CVE-2026-46595、CVE-2026-46597 和 CVE-2026-46598。
- 修正 net-misc/wget 中的 CVE-2026-58470。
- 修正 dev-python/setuptools 中的 CVE-2026-59890。
- 修正 Linux 核心中的多項安全漏洞:CVE-2026-64227、CVE-2026-64244、CVE-2026-64247、CVE-2026-64265、CVE-2026-64266、CVE-2026-64284、CVE-2026-64289、CVE-2026-64294、CVE-2026-64298、CVE-2026-64299、CVE-2026-64306、CVE-2026-64313、CVE-2026-64317、CVE-2026-64319、CVE-2026-64322、CVE-2026-64323、CVE-2026-64324、CVE-2026-64326、CVE-2026-64354、CVE-2026-64357、CVE-2026-64368、CVE-2026-64370、CVE-2026-64373、CVE-2026-64378、CVE-2026-64379、CVE-2026-64381、CVE-2026-64382、CVE-2026-64383、CVE-2026-64384、CVE-2026-64385、CVE-2026-64386、CVE-2026-64387、CVE-2026-64411、CVE-2026-64412、CVE-2026-64414、CVE-2026-64415、CVE-2026-64418、CVE-2026-64422、CVE-2026-64423、CVE-2026-64425、CVE-2026-64432、CVE-2026-64435、CVE-2026-64436、CVE-2026-64448、CVE-2026-64456、CVE-2026-64473、CVE-2026-64474、CVE-2026-64475、CVE-2026-64512 和 CVE-2026-64514。
- 將 net-libs/nghttp2 升級至 1.69.0,修正 CVE-2026-58055。
- 修正 sys-apps/systemd 中的 CVE-2026-29111。
- 修正 dev-lang/python 中的 CVE-2026-3644 和 CVE-2026-6019。
- 修正 app-crypt/mit-krb5 中的 CVE-2026-40355 和 CVE-2026-40356。
- 修正 Linux 核心中的多項安全漏洞:CVE-2026-53381、CVE-2026-53385、CVE-2026-53388、CVE-2026-53391、CVE-2026-53392、CVE-2026-53393、CVE-2026-53394、CVE-2026-53397、CVE-2026-53398、CVE-2026-53400、CVE-2026-63795、CVE-2026-63800、CVE-2026-63802、CVE-2026-63806、CVE-2026-63807、CVE-2026-63809、CVE-2026-63810、CVE-2026-63823、CVE-2026-63824、CVE-2026-63827、CVE-2026-63828、CVE-2026-63829、CVE-2026-63830、CVE-2026-63833、CVE-2026-64187 和 CVE-2026-64189。
- 修正 openssh 中的多項安全漏洞:CVE-2026-59995、CVE-2026-59996、CVE-2026-59997、CVE-2026-59999、CVE-2026-60000、CVE-2026-60001 和 CVE-2026-60002。
- 修正 glib 中的 CVE-2026-58013、CVE-2026-58014、CVE-2026-58015 和 CVE-2026-58016。
- 修正 Linux 核心中的 CVE-2026-43010 和 CVE-2026-43216。
- 修正 wget 中的 CVE-2026-58469、CVE-2026-58471 和 CVE-2026-58472。
- 透過 containerd 更新至 v2.1.9,解決 CVE-2026-46680、CVE-2026-50195、CVE-2026-53492 和 CVE-2026-53488。
- 修正 Linux 核心中的 CVE-2026-53341。
- 修正 Linux 核心中的 KCTF-736b380。
- 其他:
- 將 OS 映像檔元件與 COS 版本 125-19216-532-25 同步。
- 已將基本映像檔更新為 cos-gb300-bm-125-19216-532-14。