Database/Container, Kubernetes & orchestration
BuildKit: invalid SecurityMode disables Seccomp and AppArmor without the insecure entitlement
Impact
A custom frontend can place an unsupported SecurityMode value in a crafted build request; spec_linux.go treats the unrecognized value as a non-sandbox mode and skips the security.insecure entitlement check. The build container then runs with Seccomp and AppArmor off. Linux capabilities remain restricted, so this is not a direct escape, but it strips two of the layers standing between an untrusted build and the host kernel and widens the syscall surface a kernel exploit can reach. On a shared build farm — including GPU nodes doing image builds alongside tenant workloads — the entitlement system exists so the operator decides which builds get to drop sandboxing; this bypasses that decision without any signal.
Who can reach it
Anyone who can submit a build request with a custom frontend to the BuildKit daemon. Network-reachable and low-privileged in the usual buildkitd-as-a-shared-service deployment.
What to do
Upgrade BuildKit to 0.31.1 and restart buildkitd, or update the builder image if you run BuildKit as a Kubernetes builder deployment. No node drain or reboot. If you allow untrusted or third-party frontends, review who can submit builds while rolling the fix.
References
Related entries
- JFrog Artifactory: authenticated write outside the Docker repository cache pathCVE-2026-66384 · JFrog Artifactory (Docker remote repository cache path)Medium
- Envoy: path normalization misses ..;param segments, bypassing path-based routing and RBACCVE-2026-73551 · Envoy (URL path normalization, dot segments with semicolon parameters)Medium
- Rancher Fleet: Helm template preprocessing reaches the network, leaking cluster metadata via DNSCVE-2026-75036 · Rancher Fleet controller (Helm template preprocessing / GitRepo bundle content)Medium
- containerd: containerd-shim abstract-socket API exposed to host-network containersCVE-2020-15257 · containerdMedium
- Kubernetes (kube-apiserver): Aggregated API server can redirect apiserver clientsCVE-2022-3172 · Kubernetes (kube-apiserver)Medium
- Docker / moby: On firewalld reload, published container ports become reachable from outside despite the intendedCVE-2025-54388 · Docker / mobyMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.