BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

Project Subscriptions

Vendors Products
Buildkit Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

Avoid untrusted builds. Rootless mode mitigates device access but not denial of service.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Moby
Moby buildkit
Vendors & Products Moby
Moby buildkit

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Title BuildKit improperly handles special files in build snapshots
Weaknesses CWE-441
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-05T18:52:25.223Z

Reserved: 2026-09-17T17:18:00.217Z

Link: CVE-2026-93320

cve-icon Vulnrichment

Updated: 2026-10-05T18:52:16.741Z

cve-icon NVD

Status : Received

Published: 2026-10-05T18:17:38.353

Modified: 2026-10-05T19:17:26.177

Link: CVE-2026-93320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:00:18Z

Weaknesses