CVE-2026-93323

Summary

The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.

Affected Software

VendorProductVersion RangeStatus
mobyBuildKit0 <= 0.33.0affected

Weaknesses

  • CWE-789: CWE-789: Memory Allocation with Excessive Size Value

Workarounds

Only build from trusted build contexts. Run buildkitd under a memory limit (cgroup or container limit) so exhaustion is contained to the daemon.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References