Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33747

Опубликовано: 27 мар. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with #syntax or --build-arg BUILDKIT_SYNTAX. Using these options with a well-known frontend image like docker/dockerfile is not affected.

A flaw was found in BuildKit, a toolkit for converting source code to build artifacts. An untrusted BuildKit frontend can be leveraged to craft a malicious API message, allowing files to be written outside of the designated BuildKit state directory. This vulnerability, which is a form of arbitrary file write, could enable an attacker to execute unauthorized code or escalate their privileges on the system. This issue arises when custom BuildKit frontends are used with specific configuration options.

Меры по смягчению последствий

To mitigate this vulnerability, avoid using untrusted BuildKit frontends. Restrict the use of custom BuildKit frontends to only those from verified and trusted sources. Do not specify untrusted frontends via #syntax or --build-arg BUILDKIT_SYNTAX.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-must-gather-rhel9Affected
Kernel Module Management Operator for Red Hat Openshiftkmm/kernel-module-management-must-gather-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorWill not fix
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorNot affected
Logical Volume Manager Storagelvms4/lvms-must-gather-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-cli-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-discovery-addon-rhel9Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-log-reader-rhel8Affected
Migration Toolkit for Containersrhmtc/openshift-migration-must-gather-rhel8Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2452076BuildKit: github.com/moby/buildkit: BuildKit: Arbitrary file write and code execution via untrusted frontend

EPSS

Процентиль: 40%
0.00498
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
ubuntu
4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.4
nvd
4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.4
debian
4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in ...

CVSS3: 8.4
github
4 месяца назад

BuildKit's Malicious frontend can cause file escape outside of storage root

CVSS3: 9.8
fstec
4 месяца назад

Уязвимость программного средства сборки контейнеров BuildKit, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 40%
0.00498
Низкий

8.2 High

CVSS3