Database/Container, Kubernetes & orchestration
BuildKit: external frontend using the internal API triggers a data race that panics buildkitd
Impact
A malicious external BuildKit frontend can issue requests over the daemon's internal API in a pattern that creates a data race, panicking buildkitd. Every build on that instance dies with the process. The exposure depends on running external frontends - a build that pulls its frontend image from an untrusted registry, or a pipeline that lets callers pick the frontend - which is the common case in multi-tenant CI that builds GPU and inference images. Availability only; no disclosure or code execution is claimed. Being a race, it is not guaranteed to fire on a single attempt.
Who can reach it
An external frontend image executed by the daemon, driven by a caller with build-submit access (CVSS PR:L). Attack complexity includes a race condition (AT:P).
What to do
Upgrade BuildKit to v0.33.1 and restart buildkitd; in-flight builds are lost. Meanwhile, pin frontends to images from a registry you control and reject caller-supplied #syntax= directives on the shared builder.
References
Related entries
- BuildKit: NTFS junctions inside the cache root escape the cache mount on Windows container workersCVE-2026-15788 · BuildKitMedium
- containerd: CRI checkpoint import does not validate image references in checkpoint metadataCVE-2026-50195 · containerdMedium
- Kubernetes (kubelet): Pod writes to its own /etc/hosts unaccounted for in evictionCVE-2020-8557 · Kubernetes (kubelet)Medium
- Calico: Route hijacking via the floating IP featureCVE-2022-28224 · CalicoMedium
- containerd: Unbounded memory consumption in containerd daemon via repeated ExecSyncCVE-2022-31030 · containerdMedium
- cosign / sigstore: Multiple verify-blob flaws cause successful verification of unsigned or wrongly-signed artifactsCVE-2022-36056 · cosign / sigstoreMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.