Database/Container, Kubernetes & orchestration
BuildKit: unbounded /etc/passwd read from a build image OOM-kills the buildkitd daemon
Impact
buildkitd reads /etc/passwd and /etc/group from the build context with no size limit while resolving a USER directive, so a base image carrying an oversized passwd file exhausts memory and the daemon is OOM-killed. On a shared build host that takes every tenant's builds, one crafted base image kills the daemon for everyone and drops in-flight builds. It is availability-only - no code execution or data exposure is claimed - but a build fleet that also schedules image builds for GPU jobs stalls the job pipeline behind it.
Who can reach it
Anyone who can get BuildKit to build a Dockerfile referencing an attacker-supplied base image, or submit a build definition. The CVSS vector marks user interaction as required and no privileges, matching the case where an operator builds an untrusted image.
What to do
Upgrade BuildKit to 0.31.1 or later (commits 408266e and 69a3924) and restart buildkitd; queued builds must be resubmitted. Until then, restrict which registries and base images the builder will pull, and run buildkitd under a memory cgroup so an OOM kill takes only the builder rather than the host.
References
Related entries
- Kubernetes (kube-apiserver): TOCTOU/DNS-rebinding bypass of the link-local and localhost proxy protectionsCVE-2020-8562 · Kubernetes (kube-apiserver)Low
- BuildKit: Crafted low-level API message deletes the contents of the host /tmpCVE-2026-15791 · BuildKitLow
- Argo Workflows (controller, expression template evaluation of input parameters): When EXPRESSION_TEMPLATES is on andCVE-2021-37914 · Argo Workflows (controller, expression template evaluation of input parameters)Unscored
- Apache CloudStack CKS: cross-tenant manipulation of Kubernetes clusters when adding or removing nodesCVE-2026-62440 · Apache CloudStack Kubernetes Service (CKS) plugin - node add/remove pathUnscored
- Argo Workflows (Argo Server, TLS keys baked into the container image): Argo Server's TLS private keys ship inside theNCVD-2021-013-argo-workflows-argo-server-tls-k · Argo Workflows (Argo Server, TLS keys baked into the container image)Unscored
- Argo Workflows (Argo Server, --auth-mode=client on Kubernetes 1.19+ outside a pod): In this configuration the client'sNCVD-2021-014-argo-workflows-argo-server-auth · Argo Workflows (Argo Server, --auth-mode=client on Kubernetes 1.19+ outside a pod)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.