如果 BuildKit 守护进程在启动时使用了 参数,那么在构建尝试使用 CDI 设备时,可能会导致守护进程发生恐慌(panic)。这种情况可能是恶意触发的,也可能是无意中发生的。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93318 | 7.5 HIGH | Cache poisoning via unvalidated image layer DiffIDs |
| CVE-2026-93322 | 6.9 MEDIUM | Malformed MergeOp can crash the BuildKit daemon |
| CVE-2026-93323 | 6.8 MEDIUM | Oversized Dockerfile or .dockerignore can exhaust buildkitd memory |
| CVE-2026-93320 | 6.0 MEDIUM | BuildKit improperly handles special files in build snapshots |
| CVE-2026-93326 | 6.0 MEDIUM | Crafted Git build source can bypass certain policy validation |
| CVE-2026-93317 | 5.9 MEDIUM | Container blob cache can accept unverified content |
| CVE-2026-93319 | 5.7 MEDIUM | A malicious frontend can cause a daemon panic |
No comments yet