[EMK] Garden Linux: out-of-band image release addressing CVE-2026-31431 (copy.fail)

Scheduled Maintenance Report for Cyso Cloud

Completed

The scheduled maintenance has been completed.
Posted May 01, 2026 - 13:15 CEST

In progress

Scheduled maintenance is currently in progress. We will provide updates as necessary.
Posted May 01, 2026 - 11:15 CEST

Scheduled

SUMMARY

New Garden Linux images have been released outside the regular maintenance schedule to address a critical security vulnerability. This is an unplanned, emergency update and customers are advised to migrate to the patched images as soon as possible.

VULNERABILITY

CVE-2026-31431 - Also known as Copy Fail, allowing privilege escalation. See the disclosure page (https://copy.fail/) for more information.

AFFECTED IMAGE TRACKS & UPDATED VERSIONS

Track 1877: 1877.14.0 → 1877.16.0
Track 2150: 2150.1.0 → 2150.2.0

SCOPE

Only Garden Linux images are affected by this vulnerability. Flatcar
Container Linux is not affected, and no action is required for
Flatcar-based workers.

RECOMMENDED ACTIONS

We recommend all customers to migrate their workers to one of the unaffected versions, if you have configured automated maintenance your workers will automatically be updated to the newer versions. Though we urge you to roll out these changes as soon as possible, due to the nature of containerized workloads and the execution of third party (base) images.
Posted May 01, 2026 - 11:12 CEST
This scheduled maintenance affected: Enterprise Managed Kubernetes Services.