CVE-2026-93323: fallo de gravedad media en moby BuildKit
Oversized Dockerfile or .dockerignore can exhaust buildkitd memory
Publicada el
13Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 6.8epss 0.1%
probabilidad de explotación
0.1%top 99% de las CVE
explotación observada
noninguna fuente lo reporta
The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Productos afectados
moby · BuildKitCVEs relacionadas — moby BuildKit
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-15788MEDIUMWCOW cache mount source selector resolves NTFS junctions outside of cache rootEPSS 0.4%CVE-2026-15789MEDIUMMalicious client can bypass destination directory validation on local sources uploadEPSS 0.3%CVE-2026-93326MEDIUMCrafted Git build source can bypass certain policy validationEPSS 0.2%CVE-2026-15791LOWLLB file operation can be tricked to remove /tmp directory contentsEPSS 0.2%CVE-2026-15792MEDIUMPossible panic when incorrect parameters sent from frontendEPSS 0.2%CVE-2026-93316HIGHStarting daemon with --cdi-disabled flag can lead to panic on specific buildsEPSS 0.2%