Description
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Published: 2026-10-05
Score: 6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Avoid untrusted builds. Rootless mode mitigates device access but not denial of service.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Title BuildKit improperly handles special files in build snapshots
Weaknesses CWE-441
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-05T18:52:25.223Z

Reserved: 2026-09-17T17:18:00.217Z

Link: CVE-2026-93320

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T18:17:38.353

Modified: 2026-10-05T18:17:38.353

Link: CVE-2026-93320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses