A container that can reach root on the node is not a misconfigured capability. It is a kernel bug with a nickname.
Google’s GKE security bulletins list CVE-2026-46300 as a container breakout in the Linux kernel, known as Fragnesia. An unprivileged local attacker can escalate to root on the host. The impact line is the part to tape above the on-call keyboard. GKE Standard clusters with Ubuntu nodes are impacted. Standard clusters on Container-Optimized OS are not. Autopilot is not. GKE Sandbox is not. Severity on the bulletin snippet is Medium. Medium is how you describe a breakout that does not hit every node image.
I am not going to describe the exploit path. You do not need it to patch. Community write-ups put Fragnesia in the XFRM ESP-in-TCP neighborhood and next to older Dirty Frag / RxRPC IDs. If you want those names, read the bulletin and Red Hat’s tracker. If you want to keep a cluster, read the node OS column.
Who has to move
Inventory first. For every pool:
- Autopilot or Standard
- Node image: Ubuntu versus COS
- Sandbox on or off for the untrusted namespaces
- Control plane and node versions against the patched list
If the pool is Autopilot, you are not in the Ubuntu impact line. If the pool is Standard on COS, same. If the pool is Standard on Ubuntu, you are the audience. Sandbox is the extra fence Google called out as not impacted. That is not a reason to skip the node patch. It is a reason to put untrusted build jobs in a sandbox while you roll.
The Cluster Toolkit discussion on 26 July copied the Ubuntu patched versions from bulletin GCP-2026-033. Treat “or later” as the rule:
- GKE 1.36: 1.36.2-gke.1346000
- GKE 1.35: 1.35.6-gke.1127000
- GKE 1.34: 1.34.9-gke.1131000
- GKE 1.33: 1.33.13-gke.1011000
- GKE 1.32: 1.32.13-gke.1829000
- GKE 1.31: 1.31.14-gke.2116000
- GKE 1.30: 1.30.14-gke.2710000
If you are still on a 1.29 pool, you are not on this list. That is a different conversation, and it is worse.
Do not mix this CVE with Dirty Frag (CVE-2026-43284) or CVE-2026-43500. Those had their own GKE patch notes earlier in the year. Fragnesia is the Ubuntu-node follow-up. Your change ticket should name 46300 so nobody closes it as “we already did June.”
How I would roll this week
- Dump node image type and version for every pool. If you cannot do that in one command, your inventory is the incident.
- Anything Ubuntu and below the numbers above goes into a surge window. Surge and max-unavailable should be boring. This is not the night to invent a custom soak.
- Workloads that cannot tolerate a drain get a new COS pool and a migration, or they wait in a ticket with a name on it. Silent Ubuntu leftovers are how breakouts stay real after the blog post.
- Untrusted namespaces (CI, student clusters, anything that runs stranger YAML) should already be on GKE Sandbox. If they are not, this bulletin is your excuse.
- After the roll, confirm the node image ID, not the pool name. People rename pools and forget the old MIG.
I am not publishing kubectl one-liners that look like a recipe for probing the bug. kubectl get nodes -o wide and the GKE console’s node-image column are enough.
COS is not magic. It is the image Google said is outside this impact line. If your reason for Ubuntu was a Debian package you could not live without, now is a good time to ask whether that package belongs on the node or in a daemonset.
The Docker tag lesson sitting next to this
While you are in the habit of not trusting labels, Core Lightning’s v26.06.7 Docker episode is a smaller, dumber version of the same class of failure. Version 26.06.7 went out 28 August as a fixes-only point release. The project had held source during an embargo. Between 28 August 16:04 UTC and 1 September, four tags served images that printed v26.06.7 at startup and did not contain the fixes: v26.06.7, latest, v26.06.7-vls, latest-vls. The embargo ended. Source landed 2026-09-11T11:42Z. The tag string was a liar for four days.
Pin a digest. Do not pin latest. Do not assume the version banner inside the container matches the CVE you think you closed. That advice is older than Fragnesia. It is still how people get surprised.
If you build your own images on Ubuntu nodes that have not moved, you are stacking both problems: a host that can be broken out of, and a tag that might not be the patch. Split them. Patch the node. Pin the digest.
What this is not
This is not a reason to set privileged: true “just for now.” This is not a reason to disable seccomp because a sidecar complained. CrowdStrike feeding RapidFort a rebuild is the other direction: shrink the image, do not grow the permissions. Docker Hardened Images are a supply-chain conversation. Fragnesia is a kernel conversation. You want both, not a blog that pretends they are the same ticket.
It is also not the same story as last week’s CISA KEV pile. Edge appliances and a GKE node image are different queues. Do not let the KEV board steal the hour you need for the Ubuntu pools.
I am not going to rank this as “the worst GKE year.” Recap sites like that sentence. Google called it Medium and published image versions. Medium plus a host root is still a page you schedule. It is not a press release.
Checks I want in the ticket before you close it
- Every Standard Ubuntu pool is on a listed version or gone.
- Autopilot and COS pools are labeled as out of scope with a screenshot of the image family, so the next person does not re-open the panic.
- Untrusted CI is sandboxed or scheduled.
- Image tags in prod compose/helm files are digests, at least for the daemons that sit on the node network.
- Nobody pasted an exploit PoC into the Slack thread. You do not need it. The bulletin is the work.
If your cluster is not GKE, the CVE still exists in kernels that have the same XFRM path. Distro advisories are your list, not GCP-2026-033. Same rule: patch, do not reproduce.
Fragnesia is a bad name for a host breakout. The good news is Google already split the customer base by node image. The bad news is Ubuntu Standard is a lot of clusters. Roll the pools. Leave the exploit tweets alone.
Why Ubuntu nodes exist, and why that excuse is thinner this week
People pick Ubuntu on GKE because a vendor’s install script assumed apt, or because a security scanner had a nicer Ubuntu profile, or because someone wanted to ssh and debug with tools that are not on COS. Those are real reasons. They are also how you inherit kernel CVEs that COS skipped.
If the apt package is a node-level dependency (DKMS, a NIC utility, a third-party agent), ask whether it belongs in a privileged daemonset instead. If the answer is “the vendor only supports Ubuntu on the node,” put that sentence in the ticket next to CVE-2026-46300 and make the vendor look at it. If the answer is “we like bash better,” move to COS.
Multi-tenant nodes make this louder. A Standard pool that runs two teams’ CI is the textbook victim of a breakout: the unprivileged job in namespace A is supposed to be stuck in a container, and Fragnesia is the class of bug that disagrees. Sandbox is the control Google already said sits outside impact. Use it for CI even after the patch. Patches lag the next nickname.
What I want in monitoring, not in a blog comment
You will not get a clean “Fragnesia fired” metric. You get node reboots, unexpected uid 0 processes on the host, and container runtimes that look fine. If you already scrape node OS query logs or falco on the host, keep them. If you do not, this bulletin is not the week to design a detection program. It is the week to change the image.
After the roll, watch for pools that scale back to an old instance template. Autoscalers are loyal to the MIG you forgot. Pin the node image family in the pool config so a scale-out does not resurrect 1.33.12.
For the Core Lightning Docker mess, the monitoring is dumber: compare the image digest in prod to the digest you recorded when you read the advisory. If they differ, you did not pin. The version banner is decoration.
Scope discipline
Do not open a company-wide “container escape” epic that mixes Fragnesia, last year’s containerd CVEs, and a mis-set hostPID. Those are three tickets. Fragnesia is kernel plus Ubuntu node image plus GKE version. Close it when the versions match the list. Then file a separate ticket for digest pinning. Then file a third for sandbox on untrusted namespaces if that is still outstanding.
I have watched teams fail closed by writing a nine-page threat model while the Ubuntu pool sat on Friday’s version. The bulletin is short on purpose. Copy the versions. Drain the nodes. Confirm the image ID. That is the work.
If you are on EKS or a homelab kubeadm, stop reading GKE version strings as if they apply. Your distro’s kernel advisory is the list. Same refusal to publish a repro. Same urge to patch before you read a nickname thread.
The name will trend for a day. The Ubuntu column will still be there on Monday. Be on the patched side of it.
If you only have time for one command this morning, it is not a blog search. It is listing node images. If the string says ubuntu and the version is below the list, drain. If the string says cos or the cluster is Autopilot, write “out of scope” on the ticket with a screenshot and go back to the KEV board. That is the whole article, with citations.