Database/Container, Kubernetes & orchestration
BuildKit: image can advertise another image's DiffIDs, poisoning shared build cache
Impact
A malicious image can advertise DiffIDs belonging to a different image while shipping different layer contents, and BuildKit derived cache and snapshot identity from the advertised DiffIDs without checking them against the actual layers. On a BuildKit daemon with shared or persistent cache - the normal setup for a build farm or a CI runner pool - processing the malicious image first means a later build of a victim image mounts attacker-controlled layer content as its base. Replacing something routinely executed such as /bin/sh gets the attacker's code running inside the victim build, where it can read mounted build secrets, reach other build resources, tamper with output artifacts, or hang the build. For a GPU fleet this is a supply-chain foothold in the images that later run on the nodes, and registry credentials or model-pull tokens mounted as build secrets are in reach. Both regular and lazy-pulling snapshotters such as stargz are affected.
Who can reach it
Anyone who can get a BuildKit daemon with shared or persistent cache to process an image they control - a build job, a PR pipeline, or a tenant-submitted Dockerfile. No privileges on the host are needed.
What to do
Upgrade BuildKit to v0.33.1 and restart buildkitd. Because the flaw corrupts cache identity, purge the shared or persistent build cache after upgrading rather than trusting existing entries, and stop reusing a single cache across trust boundaries.
References
Related entries
- Envoy: Type-confusion in default certificate validationCVE-2022-21656 · EnvoyHigh
- Rancher: Missing authorization allows an authenticated user to create a shell pod with kubectl accessCVE-2022-21953 · RancherHigh
- CRI-O: restored checkpoints re-apply archive mounts, bypassing pod-spec host mount validationCVE-2024-8676 · CRI-O (container checkpoint/restore endpoint)High
- Podman: files written to bind mounts during build persist in the host build context directoryCVE-2025-4953 · Podman (podman build, RUN --mount=type=bind)High
- Strimzi: generated Role grants Kafka Connect and MirrorMaker 2 GET on all Secrets in the namespaceCVE-2025-66623 · Strimzi Kafka Operator (generated Role for Kafka Connect / MirrorMaker 2)High
- BentoML (bentofile.yaml path fields: description, docker.setup_script, docker.dockerfile_templateCVE-2026-24123 · BentoMLHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.