Dockerfile 前端在加载构建上下文中的 Dockerfile 和 .dockerignore 文件到内存时,未设置大小限制。如果构建上下文中包含超大文件,可能导致 buildkitd 分配与该文件成比例的内存,从而耗尽内存并终止守护进程,进而中断在同一实例上运行的其他构建操作。该问题已通过拒绝加载超过 16 MiB 的文件来修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93318 | 7.5 HIGH | Cache poisoning via unvalidated image layer DiffIDs |
| CVE-2026-93316 | 7.1 HIGH | Starting daemon with --cdi-disabled flag can lead to panic on specific builds |
| CVE-2026-93322 | 6.9 MEDIUM | Malformed MergeOp can crash the BuildKit daemon |
| CVE-2026-93320 | 6.0 MEDIUM | BuildKit improperly handles special files in build snapshots |
| CVE-2026-93326 | 6.0 MEDIUM | Crafted Git build source can bypass certain policy validation |
| CVE-2026-93317 | 5.9 MEDIUM | Container blob cache can accept unverified content |
| CVE-2026-93319 | 5.7 MEDIUM | A malicious frontend can cause a daemon panic |
No comments yet