Description
If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.
No analysis available yet.
Remediation
Vendor Workaround
The issue only appears when --cdi-disabled is set as a specific flag in daemon startup or TOML config. Without it, builds get regular entitlement checks and fail cleanly if the user doesn't allow specific CDI entitlements per build.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 05 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident. | |
| Title | Starting daemon with --cdi-disabled flag can lead to panic on specific builds | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-05T17:42:12.969Z
Reserved: 2026-09-17T17:17:35.128Z
Link: CVE-2026-93316
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-476
NULL Pointer Dereference