GPU VulnDB

Database/Container, Kubernetes & orchestration

BuildKit: oversized Dockerfile or .dockerignore exhausts buildkitd memory and kills concurrent builds

CVSS 6.8CVE-2026-93323Container, Kubernetes & orchestrationcurated

Impact

The Dockerfile frontend read the Dockerfile and .dockerignore out of the build context with no size cap, allocating memory proportional to the file. A build context carrying a multi-gigabyte file of either name can drive buildkitd into memory exhaustion and terminate it, taking down every other build running on that instance. For an operator this is a shared-CI availability problem: the daemon that builds GPU driver and inference images is a single process shared across pipelines, and an OOM kill does not distinguish tenants. Confidentiality and integrity are unaffected. The fix rejects such files above 16 MiB.

Who can reach it

Any authenticated caller who can submit a build context to the shared buildkitd (CVSS PR:L) - a CI job, a developer with build access, or a repository whose contents are built automatically.

What to do

Upgrade BuildKit to v0.33.1, which caps these files at 16 MiB, and restart buildkitd. Restart drops in-flight builds; no node drain or reboot needed. Interim mitigation is to cap build-context size or memory-limit the buildkitd container so an OOM kill is contained.

References

Related entries

All Container, Kubernetes & orchestration entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.