Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-75593

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.

A flaw was found in BuildKit, a toolkit for converting source code to build artifacts. A malicious client with valid permissions to access the BuildKit control API can craft a special upload request. This request allows files to escape from the BuildKit-controlled state directory, potentially leading to unauthorized modification or deletion of files on the system.

Отчет

A flaw in BuildKit allows a client with valid permissions to the BuildKit control API to perform unauthorized file modifications outside the intended build state directory. This issue is limited to authenticated clients, reducing the overall attack surface.

Меры по смягчению последствий

Restrict access to the BuildKit control API to only trusted users and services. Implement robust authentication and authorization policies for all clients interacting with the BuildKit daemon to prevent unauthorized access and potential file system escapes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Assisted Installer for Red Hat OpenShift Container Platform 2assisted/agent-preinstall-image-builder-rhel9Not affected
Assisted Installer for Red Hat OpenShift Container Platform 2rhai/assisted-installer-controller-rhel9Affected
Compliance Operatorcompliance/openshift-compliance-must-gather-rhel8Affected
Confidential Compute Attestationbuild-of-trustee/trustee-must-gather-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-must-gather-rhel9Affected
Confidential Compute Attestationopenshift-sandboxed-containers/osc-podvm-builder-rhel9Affected
Kernel Module Management Operator for Red Hat Openshiftkmm/kernel-module-management-must-gather-rhel9Affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/cluster-logging-rhel9-operatorAffected
Logical Volume Manager Storagelvms4/lvms-must-gather-rhel8Affected
Logical Volume Manager Storagelvms4/lvms-must-gather-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2519913github.com/moby/buildkit: BuildKit: File escape vulnerability allows unauthorized file modification

EPSS

Процентиль: 44%
0.0054
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

nvd
29 дней назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.

msrc
26 дней назад

BuildKit: Malicious client can bypass destination directory validation on local sources upload

debian
29 дней назад

BuildKit is a toolkit for converting source code to build artifacts in ...

github
29 дней назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory. The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.

EPSS

Процентиль: 44%
0.0054
Низкий

6.5 Medium

CVSS3