Description
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Published: 2026-10-05
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Avoid untrusted builds. Rootless mode mitigates device access but not denial of service.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Title BuildKit improperly handles special files in build snapshots
Weaknesses CWE-441
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-05T18:52:25.223Z

Reserved: 2026-09-17T17:18:00.217Z

Link: CVE-2026-93320

cve-icon Vulnrichment

Updated: 2026-10-05T18:52:16.741Z

cve-icon NVD

Status : Received

Published: 2026-10-05T18:17:38.353

Modified: 2026-10-05T19:17:26.177

Link: CVE-2026-93320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')