CVE-2026-93316

Summary

If BuildKit daemon is started with –cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.

Affected Software

VendorProductVersion RangeStatus
mobyBuildKit0 < 0.33.1affected

Weaknesses

  • CWE-476: CWE-476: NULL Pointer Dereference

Workarounds

The issue only appears when –cdi-disabled is set as a specific flag in daemon startup or TOML config. Without it, builds get regular entitlement checks and fail cleanly if the user doesn't allow specific CDI entitlements per build.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References