SB2026100259 - Multiple vulnerabilities in BuildKit



SB2026100259 - Multiple vulnerabilities in BuildKit

Published: October 2, 2026

Security Bulletin ID SB2026100259
CSH Severity
High
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 20% Medium 30% Low 50%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-93315)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to a time-of-check, time-of-use (TOCTOU) race condition. A local user can manipulate the CA bundle during build steps to disrupt cleanup operations.


2) Incorrect Behavior Order: Validate Before Canonicalize (CVE-ID: CVE-2026-93326)

CWE-ID: CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to improper repository URL validation in Git build source policy engine. A remote user can bypass URL-based policy rules and clone repositories from unauthorized remotes.


3) Uncontrolled Memory Allocation (CVE-ID: CVE-2026-93323)

CWE-ID: CWE-789 - Uncontrolled Memory Allocation

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to the lack of size limits when loading Dockerfile and .dockerignore files. A local user can cause a denial of service (DoS) condition on the target system.


4) Improper Validation of Array Index (CVE-ID: CVE-2026-93322)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A local attacker can submit the LLB definition that causes buildkitd to panic and terminate, leading to denial of service condition.


5) Improper Validation of Array Index (CVE-ID: CVE-2026-93321)

CWE-ID: CWE-129 - Improper Validation of Array Index

CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A local attacker can submit the LLB definition that causes buildkitd to panic and terminate, leading to denial of service condition.


6) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-93320)

CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')

CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to improper handling of special files in build snapshots. A remote attacker can gain access to host devices on rootful workers or cause a denial of service (DoS) condition.


7) Unsynchronized access to shared data in a multithreaded context (CVE-ID: CVE-2026-93319)

CWE-ID: CWE-567 - Unsynchronized Access to Shared Data in a Multithreaded Context

CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to unsynchronized access to shared data in a multithreaded context. A local user can send specially crafted requests using the internal API and perform a denial of service (DoS) attack.


8) Improper validation of integrity check value (CVE-ID: CVE-2026-93318)

CWE-ID: CWE-354 - Improper Validation of Integrity Check Value

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to unvalidated image layer DiffIDs. A remote attacker can provide a malicious image with forged DiffIDs and execute arbitrary code on the system.


9) Improper validation of integrity check value (CVE-ID: CVE-2026-93317)

CWE-ID: CWE-354 - Improper Validation of Integrity Check Value

CVSSv4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to improper validation of integrity check value. A remote user can provide unverified blob contents matching a claimed digest to poison the shared blob cache.


10) Input validation error (CVE-ID: CVE-2026-93316)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input in the daemon when configured with --cdi-disabled. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.


Remediation

Install update from vendor's website.