Impact
A malicious BuildKit frontend can issue calls to the internal API, creating a data race that triggers a panic in the BuildKit daemon. The result is a crash that stops all ongoing builds and can potentially disrupt availability of the infrastructure that relies on BuildKit. The vulnerability is a CWE‑567 race condition that affects concurrency control within the daemon.
Affected Systems
The issue affects the moby BuildKit product, wherever it is deployed. Any installation that uses external frontends is vulnerable; Dockerfile builds that rely solely on the built‑in frontend remain unaffected. No specific version ranges are defined in the advisory, so all current builds that accept external frontends should be considered at risk.
Risk and Exploitability
The CVSS score of 5.7 indicates moderate severity. The EPSS score is not available, so the exact likelihood of exploitation is unknown, but the vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker who can supply or influence an external frontend for the BuildKit daemon, making the threat primarily internal or supply‑chain oriented. Given the lack of public exploitation evidence and the moderate score, the overall risk is considered moderate but should be mitigated promptly.
OpenCVE Enrichment