Security Advisory: CVE-2026-31431 (Copy Fail), CVE-2026-43284 (Dirty Frag), CVE-2026-46300 (Fragnesia) #5663
Replies: 3 comments
|
Vulnerability Details & Manual Mitigations for Slurm Clusters (Optional) For users managing Slurm/Compute Engine clusters with Ubuntu as the base OS who are interested in additional vulnerability analysis or official manual mitigation steps, please refer directly to the official Canonical advisories. Applying these mitigations is at the user's discretion based on specific cluster requirements:
|
Security Advisory (June 3, 2026): Mitigations for GKE "Copy Fail" (CVE-2026-31431)Hello everyone, Following up on our initial notification, we are releasing guidance and GKE version mapping to help our community apply security updates for the Linux kernel Copy Fail vulnerability (CVE-2026-31431) in GKE environments. Standard Cluster Toolkit blueprints deploy resources into GKE's default REGULAR release channel. These clusters will automatically receive security updates as part of GKE's standard release cycle. However, if your security policies require immediate proactive mitigation, you can explicitly pin your cluster to a patched version. To help you do this safely without disrupting workloads or causing Terraform state drift, we have published a comprehensive GKE Upgrade User Guide Patched GKE Version RangesThe following GKE patch versions (or later) containing the security updates are officially published in GKE Security Bulletin GCP-2026-026:
High-Level Upgrade WorkflowsPlease refer to the GKE Upgrade User Guide for the complete, step-by-step upgrade procedures. The guide outlines two upgrade pathways depending on your operational requirements:
Distributed Workload Advisory: If you are upgrading GKE node pools currently running active GPU or TPU training workloads, please follow the workload-draining and pause warnings inside the upgrade guide to avoid job interruption. For detailed command sequences and maintenance guidelines, please review the GKE Upgrade User Guide. |
Security Advisory Update (July 26, 2026): Mitigations for GKE "Dirty Frag" (CVE-2026-43284) and "Fragnesia" (CVE-2026-46300)Hello everyone, Following up on our previous updates, GKE has now released the official patch versions addressing the remaining two vulnerabilities: Dirty Frag (CVE-2026-43284) and Fragnesia (CVE-2026-46300). If your security policies require immediate proactive mitigation, please review the patched versions below and update your clusters. Patched GKE Version RangesFor "Dirty Frag" (CVE-2026-43284) on Container-Optimized OS (COS) GKE 1.36: 1.36.0-gke.2459000 or later For "Fragnesia" (CVE-2026-46300) on Ubuntu GKE 1.36: 1.36.2-gke.1346000 or later Upgrade InstructionsTo apply these patches, please follow the exact same Blueprint-Based or Manual upgrade workflows detailed in our GKE Upgrade User Guide. For a quick summary of the steps and distributed workload advisories, please refer to the "High-Level Upgrade Workflows" section in the previous comment above. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Security Advisory
This is an Infrastructure Security Update in light of the two high-priority vulnerabilities discovered in the Linux kernel: CVE-2026-31431 (Copy Fail Vulnerability), CVE-2026-43284 (Dirty Frag Vulnerability), and CVE-2026-46300 (Fragnesia Vulnerability).
While these vulnerabilities do not reside within the Cluster Toolkit code itself, they impact the underlying Linux distributions (Ubuntu, Rocky Linux, and Debian) and Container OS.
Impact on Clusters: The risk is primarily centered on unauthorized privilege escalation and cross-tenant data exposure.
Recommended Actions: We recommend all users verify their current kernel versions against the official Google Cloud security bulletins.
Upcoming Toolkit Support: The Cluster Toolkit team is actively working on documented "how-to" guides for our users. Detailed advisories and upgrade instructions specifically tailored for GKE and Slurm Clusters will follow shortly in separate updates.
All reactions