CVE-2026-93323
6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| moby | BuildKit | 0 <= 0.33.0 | affected |
Weaknesses
- CWE-789: CWE-789: Memory Allocation with Excessive Size Value
Workarounds
Only build from trusted build contexts. Run buildkitd under a memory limit (cgroup or container limit) so exhaustion is contained to the daemon.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
- https://github.com/moby/buildkit/security/advisories/GHSA-mgqf-486f-49vp
- https://github.com/moby/buildkit/releases/tag/v0.33.1
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.