BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. The issue has been fixed in v0.12.5. Workarounds include, avoiding using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with --mount=type=cache,source=... options.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-01-31T21:49:18.041Z

Updated: 2024-08-01T23:06:25.341Z

Reserved: 2024-01-19T00:18:53.234Z

Link: CVE-2024-23651

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2024-01-31T22:15:54.183

Modified: 2024-02-09T01:43:51.767

Link: CVE-2024-23651

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-01-31T01:01:00Z

Links: CVE-2024-23651 - Bugzilla