Database/Container, Kubernetes & orchestration
BuildKit: oversized Dockerfile or .dockerignore exhausts buildkitd memory and kills concurrent builds
Impact
The Dockerfile frontend read the Dockerfile and .dockerignore out of the build context with no size cap, allocating memory proportional to the file. A build context carrying a multi-gigabyte file of either name can drive buildkitd into memory exhaustion and terminate it, taking down every other build running on that instance. For an operator this is a shared-CI availability problem: the daemon that builds GPU driver and inference images is a single process shared across pipelines, and an OOM kill does not distinguish tenants. Confidentiality and integrity are unaffected. The fix rejects such files above 16 MiB.
Who can reach it
Any authenticated caller who can submit a build context to the shared buildkitd (CVSS PR:L) - a CI job, a developer with build access, or a repository whose contents are built automatically.
What to do
Upgrade BuildKit to v0.33.1, which caps these files at 16 MiB, and restart buildkitd. Restart drops in-flight builds; no node drain or reboot needed. Interim mitigation is to cap build-context size or memory-limit the buildkitd container so an OOM kill is contained.
References
Related entries
- Kubernetes (kube-apiserver): A node can delete itself, and cascade-delete other objects, by adding an OwnerReferenceCVE-2025-5187 · Kubernetes (kube-apiserver)Medium
- JFrog Artifactory Helm chart: generated TLS private keys retained in rendered manifestsCVE-2026-66016 · JFrog Artifactory self-hosted Helm deployment (generated TLS private keys)Medium
- Kubernetes (kube-apiserver): Node address not verified when proxyingCVE-2022-3294 · Kubernetes (kube-apiserver)Medium
- Argo CD (Helm OCI repository credential logging): CREDENTIAL DISCLOSURE THROUGH THE LOG PIPELINE: Argo CD wrote theNCVD-2021-016-argo-cd-helm-oci-repository-cred · Argo CD (Helm OCI repository credential logging)Medium
- Helm: Path traversal in `helm fetch --untar` writes outside the target directoryCVE-2019-1000008 · HelmMedium
- Kubernetes (kubectl): `kubectl cp` path traversal from a malicious container tar overwrites files on the operator'sCVE-2019-11246 · Kubernetes (kubectl)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.