CVE-2026-93316
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
If BuildKit daemon is started with –cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| moby | BuildKit | 0 < 0.33.1 | affected |
Weaknesses
- CWE-476: CWE-476: NULL Pointer Dereference
Workarounds
The issue only appears when –cdi-disabled is set as a specific flag in daemon startup or TOML config. Without it, builds get regular entitlement checks and fail cleanly if the user doesn't allow specific CDI entitlements per build.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/moby/buildkit/security/advisories/GHSA-r456-g3gm-cvxf
- https://github.com/moby/buildkit/releases/tag/v0.33.1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.