GCP-2026-046
Cybersecurity Classified by Officially
A virtualization vulnerability has been identified in the KVM x86 shadow paging and nested virtualization configurations. Because an attacker operating a virtual machine with nested virtualization could escape hypervisor boundary isolation to compromise the underlying physical host, any x86 virtual machine (whether nested or non-nested) hosted on an Intel-based server supporting nested virtualization is potentially exposed.
Google is deploying live hypervisor hotpatches across all managed Compute Engine host servers globally. No action is required for managed Compute Engine virtual machines or Google Kubernetes Engine clusters. Because remediation is performed transparently at the physical host hypervisor level, customer VM downtime, reboots, or manual upgrades are not required.
Customers operating self-managed virtualized environments or custom host hypervisors outside standard managed Compute Engine infrastructure should ensure their host Linux kernel is updated with the upstream patch as soon as it is made available by their operating system vendor.
What vulnerabilities are being addressed?
This is an extract. The publication continues at the source.
Read the original at the source: https://docs.cloud.google.com/support/bulletins/index#gcp-2026-046
Officially imported this from Google’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
5 versions recorded. The original is kept in full — nothing is overwritten.
- v5 imported change on current
- v4 imported change on
- v3 imported change on
- v2 imported change on
- v1 as first published on
Provenance
- Organization
- Google — imported from official source
- Official source
- https://cloud.google.com/feeds/google-cloud-security-bulletins.xml RSS
- Imported
- September 15, 2026 20:57
- Versions
- 5 recorded
- Identity
tag:google.com,2016:google-cloud-security-bulletins#gcp-2026-046