SB2026100259 - Multiple vulnerabilities in BuildKit
Published: October 2, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 10 vulnerabilities.
1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-93315)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 5.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to a time-of-check, time-of-use (TOCTOU) race condition. A local user can manipulate the CA bundle during build steps to disrupt cleanup operations.
2) Incorrect Behavior Order: Validate Before Canonicalize (CVE-ID: CVE-2026-93326)
CWE-ID: CWE-180 - Incorrect Behavior Order: Validate Before Canonicalize
CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper repository URL validation in Git build source policy engine. A remote user can bypass URL-based policy rules and clone repositories from unauthorized remotes.
3) Uncontrolled Memory Allocation (CVE-ID: CVE-2026-93323)
CWE-ID: CWE-789 - Uncontrolled Memory Allocation
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to the lack of size limits when loading Dockerfile and .dockerignore files. A local user can cause a denial of service (DoS) condition on the target system.
4) Improper Validation of Array Index (CVE-ID: CVE-2026-93322)
CWE-ID: CWE-129 - Improper Validation of Array Index
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A local attacker can submit the LLB definition that causes buildkitd to panic and terminate, leading to denial of service condition.
5) Improper Validation of Array Index (CVE-ID: CVE-2026-93321)
CWE-ID: CWE-129 - Improper Validation of Array Index
CVSSv4: 6.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A local attacker can submit the LLB definition that causes buildkitd to panic and terminate, leading to denial of service condition.
6) Unintended Proxy or Intermediary (CVE-ID: CVE-2026-93320)
CWE-ID: CWE-441 - Unintended Proxy or Intermediary ('Confused Deputy')
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper handling of special files in build snapshots. A remote attacker can gain access to host devices on rootful workers or cause a denial of service (DoS) condition.
7) Unsynchronized access to shared data in a multithreaded context (CVE-ID: CVE-2026-93319)
CWE-ID: CWE-567 - Unsynchronized Access to Shared Data in a Multithreaded Context
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to unsynchronized access to shared data in a multithreaded context. A local user can send specially crafted requests using the internal API and perform a denial of service (DoS) attack.
8) Improper validation of integrity check value (CVE-ID: CVE-2026-93318)
CWE-ID: CWE-354 - Improper Validation of Integrity Check Value
CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to unvalidated image layer DiffIDs. A remote attacker can provide a malicious image with forged DiffIDs and execute arbitrary code on the system.
9) Improper validation of integrity check value (CVE-ID: CVE-2026-93317)
CWE-ID: CWE-354 - Improper Validation of Integrity Check Value
CVSSv4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to improper validation of integrity check value. A remote user can provide unverified blob contents matching a claimed digest to poison the shared blob cache.
10) Input validation error (CVE-ID: CVE-2026-93316)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input in the daemon when configured with --cdi-disabled. A remote user can pass specially crafted input to the application and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://github.com/moby/buildkit/security/advisories/GHSA-2f5p-x9ph-g97x
- https://github.com/moby/buildkit/security/advisories/GHSA-66hf-6vf5-87hc
- https://github.com/moby/buildkit/security/advisories/GHSA-mgqf-486f-49vp
- https://github.com/moby/buildkit/security/advisories/GHSA-cv6p-7w7g-xjwq
- https://github.com/moby/buildkit/security/advisories/GHSA-fjj4-h6vf-m9hj
- https://github.com/moby/buildkit/security/advisories/GHSA-9728-qjrv-2xh2
- https://github.com/moby/buildkit/security/advisories/GHSA-4hgw-qrhw-fhg8
- https://github.com/moby/buildkit/security/advisories/GHSA-f2v9-hprr-32q3
- https://github.com/moby/buildkit/security/advisories/GHSA-p3rc-w3hc-pqvv
- https://github.com/moby/buildkit/security/advisories/GHSA-r456-g3gm-cvxf