Database/Container, Kubernetes & orchestration
BuildKit: malicious frontend can crash buildkitd with a crafted LLB definition, killing all builds
Impact
A caller that can submit a build to buildkitd can send an LLB (low-level build) definition that panics the daemon. The daemon process terminates, so every concurrent build on that instance dies with it, including unrelated tenants' builds and the cache state in flight. On a GPU fleet this matters where buildkitd is the shared image-build backend for CI that produces CUDA/inference images: one tenant's build request stalls the pipeline that feeds node rollouts and model-server deploys. No data disclosure or code execution is claimed - this is availability only. The vendor split this across two ids (CVE-2026-93321 and CVE-2026-93322) with identical descriptions, scores, advisories and fix release; they are recorded here as one issue.
Who can reach it
Local caller able to submit a build to the buildkitd daemon - in practice any CI job, user or frontend with access to the build endpoint. The CVSS vector is AV:L/PR:N, so no authentication beyond reaching the daemon socket is required.
What to do
Upgrade BuildKit to v0.33.1 and restart buildkitd. In-flight builds are lost on restart, so schedule it between pipeline runs; no node reboot or firmware work is involved. Until then, restrict who can submit builds to the shared daemon and avoid exposing buildkitd to untrusted frontends.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- Istio: DENY AuthorizationPolicy with wildcard-suffix principals silently fails to denyCVE-2020-16844 · IstioMedium
- Docker / moby: With --userns-remap, remapped root can escalate to real host rootCVE-2021-21284 · Docker / mobyMedium
- Helm: Helm repository credentials leaked to a redirected third-party hostCVE-2021-32690 · HelmMedium
- Envoy: Envoy accepts any peer certificate rather than restricting to configured CAsCVE-2022-21657 · EnvoyMedium
- Podman: TOCTOU during volume export lets a symlink swap expose arbitrary host filesCVE-2023-0778 · PodmanMedium
- Docker / moby: Encrypted overlay network traffic can be unencrypted due to missing rulesCVE-2023-28841 · Docker / mobyMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.