Database/Container, Kubernetes & orchestration
BuildKit: special file inodes where regular files are expected give host device access on rootful workers
Impact
BuildKit can be tricked into performing file operations against special inodes - device nodes, FIFOs and similar - in places where it expects a regular file. On a rootful worker that can mean unintended access to host device files from inside a build, which is an integrity break on the build host rather than just a failed build; on other configurations the effect is operations that block or hang. Operators who run buildkitd rootful on a shared builder - common because rootless mode complicates GPU and overlay setups - should treat this as a build-to-host boundary issue. The CVSS vector records high integrity and availability impact to the subsequent system with user interaction required.
Who can reach it
A caller who can supply the build context or Dockerfile consumed by a rootful buildkitd worker. CVSS is AV:L/PR:N/UI:A - no authentication to the daemon beyond build submission, but it needs an operator or pipeline to run the crafted build.
What to do
Upgrade BuildKit to v0.33.1 and restart buildkitd. Where the shared builder handles untrusted contexts, move it to a rootless worker or an isolated, disposable build node; that is a rebuild of the builder rather than a daemon restart. No firmware or kernel work involved.
References
Related entries
- Firecracker: Network stack freezes under heavy ingressCVE-2020-16843 · FirecrackerMedium
- ingress-nginx: A tenant can overwrite another ingress's basic-auth password fileCVE-2020-8553 · ingress-nginxMedium
- Podman: Rootless containers see all traffic as coming from 127.0.0.1, defeating localhost-trust checksCVE-2021-20199 · PodmanMedium
- Docker / moby: Containers started with non-empty inheritable capabilitiesCVE-2022-24769 · Docker / mobyMedium
- runc: `runc exec --cap` created processes with non-empty inheritable capabilitiesCVE-2022-29162 · runcMedium
- Harbor: Timing condition allows creating and stopping jobs and retrieving job infoCVE-2023-20902 · HarborMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.