GPU VulnDB

Database/Container, Kubernetes & orchestration

BuildKit: external frontend using the internal API triggers a data race that panics buildkitd

CVSS 5.7CVE-2026-93319Container, Kubernetes & orchestrationcurated

Impact

A malicious external BuildKit frontend can issue requests over the daemon's internal API in a pattern that creates a data race, panicking buildkitd. Every build on that instance dies with the process. The exposure depends on running external frontends - a build that pulls its frontend image from an untrusted registry, or a pipeline that lets callers pick the frontend - which is the common case in multi-tenant CI that builds GPU and inference images. Availability only; no disclosure or code execution is claimed. Being a race, it is not guaranteed to fire on a single attempt.

Who can reach it

An external frontend image executed by the daemon, driven by a caller with build-submit access (CVSS PR:L). Attack complexity includes a race condition (AT:P).

What to do

Upgrade BuildKit to v0.33.1 and restart buildkitd; in-flight builds are lost. Meanwhile, pin frontends to images from a registry you control and reject caller-supplied #syntax= directives on the shared builder.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.