Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-33747

Опубликовано: 27 мар. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 8.4

Описание

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with #syntax or --build-arg BUILDKIT_SYNTAX. Using these options with a well-known frontend image like docker/dockerfile is not affected.

РелизСтатусПримечание
devel

needed

esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/resolute

needed

esm-infra-legacy/xenial

needed

esm-infra/xenial

ignored

end of ESM support, was needed
jammy

needed

noble

needed

Показывать по

РелизСтатусПримечание
devel

released

29.1.3-0ubuntu5
esm-apps/focal

released

26.1.3-0ubuntu1~20.04.1+esm2
esm-apps/jammy

released

29.1.3-0ubuntu3~22.04.2
esm-apps/noble

released

29.1.3-0ubuntu3~24.04.2
esm-apps/resolute

released

29.1.3-0ubuntu4.1
jammy

released

29.1.3-0ubuntu3~22.04.2
noble

released

29.1.3-0ubuntu3~24.04.2
questing

ignored

end of life, was needed
resolute

released

29.1.3-0ubuntu4.1
upstream

needs-triage

Показывать по

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.4
nvd
4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, when using a custom BuildKit frontend, the frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. The issue has been fixed in v0.28.1. The vulnerability requires using an untrusted BuildKit frontend set with `#syntax` or `--build-arg BUILDKIT_SYNTAX`. Using these options with a well-known frontend image like `docker/dockerfile` is not affected.

CVSS3: 8.4
debian
4 месяца назад

BuildKit is a toolkit for converting source code to build artifacts in ...

CVSS3: 8.4
github
4 месяца назад

BuildKit's Malicious frontend can cause file escape outside of storage root

CVSS3: 9.8
fstec
4 месяца назад

Уязвимость программного средства сборки контейнеров BuildKit, связанная с неверным ограничением имени пути к каталогу с ограниченным доступом, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

8.4 High

CVSS3