Database/Container, Kubernetes & orchestration
Docker / moby: Race in the buildkit snapshot adapter
CVSS 6.5CVE-2024-36621Container, Kubernetes & orchestrationcurated
Impact
Race in the buildkit snapshot adapter; concurrent builds leak resources and exhaust the host
Who can reach it
Anyone who can submit builds to a shared builder
What to do
Upgrade moby; isolate tenant builders
References
Related entries
- Docker / moby: /var/lib/docker subdirectories world-traversableCVE-2021-41091 · Docker / mobyMedium
- Docker / moby: Companion `docker cp` mount-setup raceCVE-2026-41568 · Docker / mobyMedium
- Docker / moby: Containers started with non-empty inheritable capabilitiesCVE-2022-24769 · Docker / mobyMedium
- Docker / moby: DNS requests from an internal network can be forwarded to external resolvers, leaking data outCVE-2024-29018 · Docker / mobyMedium
- Docker / moby: Default OCI spec does not mask /proc/acpi, so a container can change host hardware stateCVE-2018-10892 · Docker / mobyMedium
- Docker / moby: Supplementary groups not set up properlyCVE-2022-36109 · Docker / mobyMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.