GPU VulnDB

Database/Container, Kubernetes & orchestration

BuildKit: build requesting a CDI device panics a daemon started with --cdi-disabled

CVSS 7.1CVE-2026-93316Container, Kubernetes & orchestrationcurated

Impact

A buildkitd started with --cdi-disabled panics when a build tries to use a CDI device. CDI is the mechanism GPUs are handed to containers, so on a GPU build host this is reachable by anything that asks for a GPU in a build - deliberately or by a stale Dockerfile. An authenticated user who can submit builds can take down the shared daemon and every concurrent build on it; the daemon has to be restarted. Impact is availability only, with no disclosure or tampering per the vendor's scoring.

Who can reach it

Any authenticated user who can submit a build to a buildkitd instance running with --cdi-disabled, requesting a CDI device.

What to do

Upgrade BuildKit to v0.33.1 and restart buildkitd. As a mitigation, stop running with --cdi-disabled (leave CDI enabled) or block CDI device requests at the build-submission layer.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.