A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents.

If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build.

The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz.

Project Subscriptions

Vendors Products
Buildkit Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Do not share BuildKit daemon cache between trusted and untrusted builds. Use isolated BuildKit daemons or ephemeral builders for untrusted image sources, or prune BuildKit cache after processing untrusted images. Disabling stargz alone is not sufficient because regular snapshotters are also affected.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Moby
Moby buildkit
Vendors & Products Moby
Moby buildkit

Mon, 05 Oct 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description A malicious image can advertise DiffIDs from another image while containing different layer contents. In affected versions, BuildKit could use the advertised DiffIDs to derive cache and snapshot identity without validating that they matched the actual layer contents. If a BuildKit daemon with shared or persistent cache first processes such a malicious image, a later build using the victim image may mount the attacker-controlled layer contents as the base image. This can allow code from the malicious image to run in the victim build, for example by replacing a commonly executed path such as /bin/sh. The attacker-controlled code may read build secrets mounted into the build, access other build resources, alter output artifacts, or hang the build. The issue affects both regular snapshotters and lazy-pulling snapshotters such as stargz.
Title Cache poisoning via unvalidated image layer DiffIDs
Weaknesses CWE-354
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-05T19:06:41.297Z

Reserved: 2026-09-17T17:17:49.216Z

Link: CVE-2026-93318

cve-icon Vulnrichment

Updated: 2026-10-05T19:06:37.814Z

cve-icon NVD

Status : Received

Published: 2026-10-05T18:17:38.080

Modified: 2026-10-05T20:17:28.260

Link: CVE-2026-93318

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:00:21Z

Weaknesses