--- a/go.mod
+++ b/go.mod
@@ -63,10 +63,10 @@
 	github.com/xrash/smetrics v0.0.0-20240521201337-686a1a2994c1 // indirect
 	go.yaml.in/yaml/v2 v2.4.3 // indirect
 	go.yaml.in/yaml/v3 v3.0.4 // indirect
-	golang.org/x/net v0.56.0 // indirect
+	golang.org/x/net v0.58.0 // indirect
 	golang.org/x/oauth2 v0.36.0 // indirect
 	golang.org/x/sys v0.47.0 // indirect
-	golang.org/x/term v0.44.0 // indirect
+	golang.org/x/term v0.45.0 // indirect
 	golang.org/x/text v0.41.0 // indirect
 	golang.org/x/time v0.15.0 // indirect
 	google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa // indirect
@@ -79,3 +79,5 @@
 	sigs.k8s.io/randfill v1.0.0 // indirect
 	sigs.k8s.io/structured-merge-diff/v6 v6.4.0 // indirect
 )
+
+replace google.golang.org/grpc => google.golang.org/grpc v1.83.2
--- a/go.sum
+++ b/go.sum
@@ -136,14 +136,14 @@
 go.yaml.in/yaml/v3 v3.0.4/go.mod h1:DhzuOOF2ATzADvBadXxruRBLzYTpT36CKvDb3+aBEFg=
 golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs=
 golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE=
-golang.org/x/net v0.56.0 h1:Rw8j/hFzGvJUZwNBXnAtf5sVDVt+65SK2C7IxCxZt5o=
-golang.org/x/net v0.56.0/go.mod h1:D3Ku6r+V6JROoZK144D2XfMHFcMq/0zSfLelVTCFKec=
+golang.org/x/net v0.58.0 h1:ynWG7rqYi4ccpTEuPZ2QGWHktVEM9DMCj9yzDE0Q7To=
+golang.org/x/net v0.58.0/go.mod h1:YwCddHnFlT7eLQqVprV19OnhLGtc5xOKgE0RyqgfWAU=
 golang.org/x/oauth2 v0.36.0 h1:peZ/1z27fi9hUOFCAZaHyrpWG5lwe0RJEEEeH0ThlIs=
 golang.org/x/oauth2 v0.36.0/go.mod h1:YDBUJMTkDnJS+A4BP4eZBjCqtokkg1hODuPjwiGPO7Q=
 golang.org/x/sys v0.47.0 h1:o7XGOvZQCADBQQ4Y7VNq2dRWQR7JmOUW8Kxx4ZsNgWs=
 golang.org/x/sys v0.47.0/go.mod h1:4GL1E5IUh+htKOUEOaiffhrAeqysfVGipDYzABqnCmw=
-golang.org/x/term v0.44.0 h1:0rLvDRCtNj0gZkyIXhCyOb2OAzEhLVqc4B+hrsBhrmc=
-golang.org/x/term v0.44.0/go.mod h1:7ze4MdzUzLXpSAoFP1H0bOI9aXDqveSvatT5vKcFh2Y=
+golang.org/x/term v0.45.0 h1:NwWyBmoJCbfTHpxrWoZ9C6/VxOf7ic219I8xZZFdrf0=
+golang.org/x/term v0.45.0/go.mod h1:9aqxs0blBcrm/n0L9QW0aRVD+ktan8ssZromtqJC43w=
 golang.org/x/text v0.41.0 h1:vz/seA0lnX87Othu2f/0L24RcgrXD9/YFTSuGjj3rH8=
 golang.org/x/text v0.41.0/go.mod h1:jvf1O8ajNzZqhSrQBPbutR/EB83Cc0CFrezNQIwbb5M=
 golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U=
@@ -152,8 +152,8 @@
 gonum.org/v1/gonum v0.17.0/go.mod h1:El3tOrEuMpv2UdMrbNlKEh9vd86bmQ6vqIcDwxEOc1E=
 google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa h1:mZHHdPZl0dbGHCflZgAq/Q468DWVFcU2whhB2KAo8fk=
 google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8=
-google.golang.org/grpc v1.83.1 h1:HIO0+BEtBP6soyqvqC8sNUjZ7bTs+0hFQuFF+RAy++Y=
-google.golang.org/grpc v1.83.1/go.mod h1:kDyl6SKsiHKt0uylY5gtn5cEjkrIOhQOGDgIc4JGwzQ=
+google.golang.org/grpc v1.83.2 h1:EManeRomTObA0BU7I8vXgg/78uE5MJ9M8B39EX2WscU=
+google.golang.org/grpc v1.83.2/go.mod h1:YPI1hK3kDked6iHvgX3tR0y+nX/qpMFKhPgFsokw1S8=
 google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af h1:+5/Sw3GsDNlEmu7TfklWKPdQ0Ykja5VEmq2i817+jbI=
 google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
 gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
diff -Nur /work/src-orig/k8s-device-plugin/vendor/golang.org/x/net/http2/hpack/encode.go /work/src/k8s-device-plugin/vendor/golang.org/x/net/http2/hpack/encode.go
--- a/vendor/golang.org/x/net/http2/hpack/encode.go	2026-09-14 17:18:02.342696619 +0000
+++ b/vendor/golang.org/x/net/http2/hpack/encode.go	2026-09-14 17:18:25.894803220 +0000
@@ -39,7 +39,6 @@
 		tableSizeUpdate: false,
 		w:               w,
 	}
-	e.dynTab.table.init()
 	e.dynTab.setMaxSize(initialHeaderTableSize)
 	return e
 }
diff -Nur /work/src-orig/k8s-device-plugin/vendor/golang.org/x/net/http2/hpack/hpack.go /work/src/k8s-device-plugin/vendor/golang.org/x/net/http2/hpack/hpack.go
--- a/vendor/golang.org/x/net/http2/hpack/hpack.go	2026-09-14 17:18:02.342696619 +0000
+++ b/vendor/golang.org/x/net/http2/hpack/hpack.go	2026-09-14 17:18:25.894803220 +0000
@@ -105,7 +105,6 @@
 		emitEnabled: true,
 		firstField:  true,
 	}
-	d.dynTab.table.init()
 	d.dynTab.allowedMaxSize = maxDynamicTableSize
 	d.dynTab.setMaxSize(maxDynamicTableSize)
 	return d
diff -Nur /work/src-orig/k8s-device-plugin/vendor/golang.org/x/net/http2/hpack/tables.go /work/src/k8s-device-plugin/vendor/golang.org/x/net/http2/hpack/tables.go
--- a/vendor/golang.org/x/net/http2/hpack/tables.go	2026-09-14 17:18:02.342696619 +0000
+++ b/vendor/golang.org/x/net/http2/hpack/tables.go	2026-09-14 17:18:25.894803220 +0000
@@ -31,10 +31,18 @@
 
 	// byName maps a HeaderField name to the unique id of the newest entry with
 	// the same name. See above for a definition of "unique id".
+	//
+	// byName and byNameValue are used only by search, which is only called
+	// for tables used by encoders. For tables used only by decoders, the
+	// maps are never built, as a memory optimization for servers with many
+	// mostly-idle connections, each pinning a dynamic table. The maps are
+	// built lazily by the first search call and are nil until then. The two
+	// maps are always both nil or both non-nil.
 	byName map[string]uint64
 
 	// byNameValue maps a HeaderField name/value pair to the unique id of the newest
 	// entry with the same name and value. See above for a definition of "unique id".
+	// See byName for when this map is non-nil.
 	byNameValue map[pairNameValue]uint64
 }
 
@@ -42,9 +50,17 @@
 	name, value string
 }
 
-func (t *headerFieldTable) init() {
-	t.byName = make(map[string]uint64)
-	t.byNameValue = make(map[pairNameValue]uint64)
+// buildMaps initializes byName and byNameValue from ents.
+func (t *headerFieldTable) buildMaps() {
+	t.byName = make(map[string]uint64, len(t.ents))
+	t.byNameValue = make(map[pairNameValue]uint64, len(t.ents))
+	for k, f := range t.ents {
+		// Map to the newest matching entry: later (newer) entries
+		// overwrite earlier ones, matching addEntry's behavior.
+		id := t.evictCount + uint64(k) + 1
+		t.byName[f.Name] = id
+		t.byNameValue[pairNameValue{f.Name, f.Value}] = id
+	}
 }
 
 // len reports the number of entries in the table.
@@ -54,9 +70,11 @@
 
 // addEntry adds a new entry.
 func (t *headerFieldTable) addEntry(f HeaderField) {
-	id := uint64(t.len()) + t.evictCount + 1
-	t.byName[f.Name] = id
-	t.byNameValue[pairNameValue{f.Name, f.Value}] = id
+	if t.byName != nil {
+		id := uint64(t.len()) + t.evictCount + 1
+		t.byName[f.Name] = id
+		t.byNameValue[pairNameValue{f.Name, f.Value}] = id
+	}
 	t.ents = append(t.ents, f)
 }
 
@@ -65,14 +83,16 @@
 	if n > t.len() {
 		panic(fmt.Sprintf("evictOldest(%v) on table with %v entries", n, t.len()))
 	}
-	for k := 0; k < n; k++ {
-		f := t.ents[k]
-		id := t.evictCount + uint64(k) + 1
-		if t.byName[f.Name] == id {
-			delete(t.byName, f.Name)
-		}
-		if p := (pairNameValue{f.Name, f.Value}); t.byNameValue[p] == id {
-			delete(t.byNameValue, p)
+	if t.byName != nil {
+		for k := 0; k < n; k++ {
+			f := t.ents[k]
+			id := t.evictCount + uint64(k) + 1
+			if t.byName[f.Name] == id {
+				delete(t.byName, f.Name)
+			}
+			if p := (pairNameValue{f.Name, f.Value}); t.byNameValue[p] == id {
+				delete(t.byNameValue, p)
+			}
 		}
 	}
 	copy(t.ents, t.ents[n:])
@@ -100,6 +120,9 @@
 //
 // See Section 2.3.3.
 func (t *headerFieldTable) search(f HeaderField) (i uint64, nameValueMatch bool) {
+	if t.byName == nil {
+		t.buildMaps()
+	}
 	if !f.Sensitive {
 		if id := t.byNameValue[pairNameValue{f.Name, f.Value}]; id != 0 {
 			return t.idToIndex(id), true
diff -Nur /work/src-orig/k8s-device-plugin/vendor/golang.org/x/net/http2/transport_wrap.go /work/src/k8s-device-plugin/vendor/golang.org/x/net/http2/transport_wrap.go
--- a/vendor/golang.org/x/net/http2/transport_wrap.go	2026-09-14 17:18:02.342696619 +0000
+++ b/vendor/golang.org/x/net/http2/transport_wrap.go	2026-09-14 17:18:25.890803202 +0000
@@ -55,7 +55,7 @@
 // Registered is called by net/http.Transport.RegisterProtocol,
 // to let us know that it understands the registration mechanism we're using.
 func (t transportConfig) Registered(t1 *http.Transport) {
-	t.t.t1 = t1
+	t.t.lazyt1 = t1
 }
 
 func (t transportConfig) DisableCompression() bool {
@@ -145,29 +145,30 @@
 
 type transportInternal struct {
 	initOnce sync.Once
-	t1       *http.Transport
+	lazyt1   *http.Transport
 }
 
-func (t *Transport) init() {
+func (t *Transport) init() *http.Transport {
 	t.initOnce.Do(func() {
-		if t.t1 != nil {
+		if t.lazyt1 != nil {
 			return
 		}
 		t1 := &http.Transport{}
 		t.configure(t1)
 	})
+	return t.lazyt1
 }
 
 func (t *Transport) configure(t1 *http.Transport) {
 	t1.RegisterProtocol("http/2", transportConfig{t})
-	// tr2.t1 is set by transportConfig.Registered.
-	if t.t1 != t1 {
+	// tr2.lazyt1 is set by transportConfig.Registered.
+	if t.lazyt1 != t1 {
 		panic("http2: net/http does not support this version of x/net/http2")
 	}
 }
 
 func (t *Transport) roundTripOpt(req *http.Request, opt RoundTripOpt) (*http.Response, error) {
-	t.init()
+	t1 := t.init()
 
 	if req.URL.Scheme == "http" && !t.AllowHTTP {
 		return nil, errors.New("http2: unencrypted HTTP/2 not enabled")
@@ -188,22 +189,23 @@
 	ctx := context.WithValue(req.Context(), http2TransportContextKey{}, t)
 	req = req.WithContext(ctx)
 
-	return t.t1.RoundTrip(req)
+	return t1.RoundTrip(req)
 }
 
 func (t *Transport) closeIdleConnections() {
-	t.init()
-	t.t1.CloseIdleConnections()
+	t1 := t.init()
+	t1.CloseIdleConnections()
 }
 
 func (t *Transport) newUserClientConn(c net.Conn) (*ClientConn, error) {
+	t1 := t.init()
 	// http.Transport's NewClientConn doesn't provide a supported way to create
 	// a connection from a net.Conn. (This might be useful to add in the future?)
 	// We're going to craftily sneak one in via the context key, with the
 	// scheme of "http/2" telling NewClientConn to look for it.
 	ctx := context.WithValue(context.Background(), netConnContextKey{}, c)
 
-	nhcc, err := t.t1.NewClientConn(ctx, "http/2", "")
+	nhcc, err := t1.NewClientConn(ctx, "http/2", "")
 	if err != nil {
 		return nil, err
 	}
@@ -235,32 +237,40 @@
 }
 
 func (cc *ClientConn) roundTrip(req *http.Request) (*http.Response, error) {
-	err := func() error {
+	haveReservation, err := func() (bool, error) {
 		cc.mu.Lock()
 		defer cc.mu.Unlock()
 		if cc.doNotReuse {
-			return errClientConnUnusable
-		}
-		cc.roundTrips++
-		if cc.reserved > 0 {
-			// We've already reserved a concurrency slot for this request.
-			cc.reserved--
-		} else if cc.cc.Reserve() != nil {
-			// We don't seem to have an available concurrency slot,
-			// so bump the pending count (requests waiting for a slot).
-			cc.pending++
+			return false, errClientConnUnusable
 		}
+
 		// ClientConn.Shutdown will not shut down the conn while
 		// cc.starting > 0 or cc.cc.InFlight() > 0.
 		//
 		// The starting state covers the gap between us deciding to
 		// start sending the request, and actually sending it.
 		cc.starting++
-		return nil
+
+		cc.roundTrips++
+		if cc.reserved == 0 {
+			// We do not have a concurrency slot reserved for this request.
+			return false, nil
+		}
+		cc.reserved--
+		return true, nil
 	}()
 	if err != nil {
 		return nil, err
 	}
+	// If we have no reservation, try to acquire one.
+	// (This must be done without cc.mu held, since Reserve may call back to the state hook.)
+	if !haveReservation && cc.cc.Reserve() != nil {
+		// We could not acquire a concurrency slot, so bump the pending count
+		// (requests waiting for a slot).
+		cc.mu.Lock()
+		cc.pending++
+		cc.mu.Unlock()
+	}
 	resp, err := cc.cc.RoundTrip(req)
 	cc.mu.Lock()
 	cc.starting--
@@ -291,16 +301,21 @@
 }
 
 func (cc *ClientConn) reserveNewRequest() bool {
+	if err := cc.cc.Reserve(); err != nil {
+		return false
+	}
+	reserved := true
 	cc.mu.Lock()
-	defer cc.mu.Unlock()
 	if cc.doNotReuse {
-		return false
+		reserved = false
+	} else {
+		cc.reserved++
 	}
-	if err := cc.cc.Reserve(); err != nil {
-		return false
+	cc.mu.Unlock()
+	if !reserved {
+		cc.cc.Release()
 	}
-	cc.reserved++
-	return true
+	return reserved
 }
 
 func (cc *ClientConn) setDoNotReuse() {
diff -Nur /work/src-orig/k8s-device-plugin/vendor/golang.org/x/net/idna/idna.go /work/src/k8s-device-plugin/vendor/golang.org/x/net/idna/idna.go
--- a/vendor/golang.org/x/net/idna/idna.go	2026-09-14 17:18:02.342696619 +0000
+++ b/vendor/golang.org/x/net/idna/idna.go	2026-09-14 17:18:25.894803220 +0000
@@ -400,7 +400,11 @@
 				// Spec says keep the old label.
 				continue
 			}
-			if unicode16 && err == nil && len(u) > 0 && isASCII(u) {
+			if err == nil && len(u) > 0 && isASCII(u) {
+				// UTS 43 pre-revision 33 doesn't classify a xn-- label
+				// which contains only ASCII characters as an error,
+				// but that's a specification bug and a security issue.
+				// Always return an error in this case.
 				err = punyError(enc)
 			}
 			isBidi = isBidi || bidirule.DirectionString(u) != bidi.LeftToRight
diff -Nur /work/src-orig/k8s-device-plugin/vendor/google.golang.org/grpc/internal/transport/http2_server.go /work/src/k8s-device-plugin/vendor/google.golang.org/grpc/internal/transport/http2_server.go
--- a/vendor/google.golang.org/grpc/internal/transport/http2_server.go	2026-09-14 17:18:02.374696764 +0000
+++ b/vendor/google.golang.org/grpc/internal/transport/http2_server.go	2026-09-14 17:18:26.034803854 +0000
@@ -522,6 +522,12 @@
 		delete(mdata, "host")
 	}
 
+	// If :authority is still missing, i.e. no host or :authority header is
+	// present, reject the request as invalid.
+	if len(mdata[":authority"]) == 0 {
+		t.writeEarlyAbort(streamID, s.contentSubtype, status.New(codes.Internal, "no host or :authority header present"), http.StatusBadRequest, !frame.StreamEnded())
+		return nil
+	}
 	if frame.StreamEnded() {
 		// s is just created by the caller. No lock needed.
 		s.state = streamReadDone
diff -Nur /work/src-orig/k8s-device-plugin/vendor/google.golang.org/grpc/version.go /work/src/k8s-device-plugin/vendor/google.golang.org/grpc/version.go
--- a/vendor/google.golang.org/grpc/version.go	2026-09-14 17:18:02.378696782 +0000
+++ b/vendor/google.golang.org/grpc/version.go	2026-09-14 17:18:26.018803781 +0000
@@ -19,4 +19,4 @@
 package grpc
 
 // Version is the current grpc version.
-const Version = "1.83.1"
+const Version = "1.83.2"
diff -Nur /work/src-orig/k8s-device-plugin/vendor/modules.txt /work/src/k8s-device-plugin/vendor/modules.txt
--- a/vendor/modules.txt	2026-09-14 17:18:02.462697162 +0000
+++ b/vendor/modules.txt	2026-09-14 17:18:26.598806405 +0000
@@ -189,7 +189,7 @@
 # golang.org/x/mod v0.40.0
 ## explicit; go 1.25.0
 golang.org/x/mod/semver
-# golang.org/x/net v0.56.0
+# golang.org/x/net v0.58.0
 ## explicit; go 1.25.0
 golang.org/x/net/http/httpguts
 golang.org/x/net/http2
@@ -208,7 +208,7 @@
 golang.org/x/sys/plan9
 golang.org/x/sys/unix
 golang.org/x/sys/windows
-# golang.org/x/term v0.44.0
+# golang.org/x/term v0.45.0
 ## explicit; go 1.25.0
 golang.org/x/term
 # golang.org/x/text v0.41.0
@@ -223,7 +223,7 @@
 # google.golang.org/genproto/googleapis/rpc v0.0.0-20260526163538-3dc84a4a5aaa
 ## explicit; go 1.25.0
 google.golang.org/genproto/googleapis/rpc/status
-# google.golang.org/grpc v1.83.1
+# google.golang.org/grpc v1.83.1 => google.golang.org/grpc v1.83.2
 ## explicit; go 1.25.0
 google.golang.org/grpc
 google.golang.org/grpc/attributes
@@ -726,3 +726,4 @@
 # tags.cncf.io/container-device-interface/specs-go v1.1.0
 ## explicit; go 1.19
 tags.cncf.io/container-device-interface/specs-go
+# google.golang.org/grpc => google.golang.org/grpc v1.83.2
