Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07149

Опубликовано: 27 мар. 2026
Источник: fstec
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

Уязвимость программного средства сборки контейнеров BuildKit связана с неверным ограничением имени пути к каталогу с ограниченным доступом. Эксплуатация уязвимости может позволить нарушителю, действующему удалённо, получить несанкционированный доступ к защищаемой информации

Вендор

Red Hat Inc.
ООО «Ред Софт»
Docker Inc.

Наименование ПО

Red Hat Quay
РЕД ОС
Red Hat Openshift Data Foundation
Red Hat OpenShift GitOps
Red Hat OpenShift Container Platform
OpenShift Developer Tools and Services
Migration Toolkit for Virtualization
OpenShift Serverless
OpenShift Dev Spaces
Migration Toolkit for Containers
OpenShift API for Data Protection
multicluster engine for Kubernetes
Red Hat OpenStack Platform
Openshift Service Mesh
Confidential Compute Attestation
Assisted Installer for Red Hat OpenShift Container Platform
Pen Drive Powered by Red Hat Lightspeed
Red Hat OpenShift AI
Migration Toolkit for Applications
BuildKit
Red Hat Build of Podman Desktop

Версия ПО

3 (Red Hat Quay)
7.3 (РЕД ОС)
4 (Red Hat Openshift Data Foundation)
- (Red Hat OpenShift GitOps)
4 (Red Hat OpenShift Container Platform)
- (OpenShift Developer Tools and Services)
- (Migration Toolkit for Virtualization)
- (OpenShift Serverless)
- (OpenShift Dev Spaces)
- (Migration Toolkit for Containers)
- (OpenShift API for Data Protection)
- (multicluster engine for Kubernetes)
18.0 (Red Hat OpenStack Platform)
3 (Openshift Service Mesh)
- (Confidential Compute Attestation)
2 (Assisted Installer for Red Hat OpenShift Container Platform)
8.0 (РЕД ОС)
- (Pen Drive Powered by Red Hat Lightspeed)
- (Red Hat OpenShift AI)
3.1 (Openshift Service Mesh)
3.2 (Openshift Service Mesh)
8 (Migration Toolkit for Applications)
до 0.28.1 (BuildKit)
- (Red Hat Build of Podman Desktop)

Тип ПО

Прикладное ПО информационных систем
Операционная система
ПО виртуализации/ПО виртуального программно-аппаратного средства
ПО программно-аппаратного средства

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 7.3
ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Критический уровень опасности (базовая оценка CVSS 2.0 составляет 10)
Критический уровень опасности (базовая оценка CVSS 3.1 составляет 9,8)

Возможные меры по устранению уязвимости

Использование рекомендаций производителя:
https://github.com/moby/buildkit/security/advisories/GHSA-4c29-8rgm-jvjj
Для РедОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-33747
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-33747

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 40%
0.00498
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Связанные уязвимости

CVSS3: 9.8
redos
3 месяца назад

Уязвимость buildkit

CVSS3: 8.4
ubuntu
4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.2
redhat
4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.4
nvd
4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.4
debian
4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in ...

EPSS

Процентиль: 40%
0.00498
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2