Description
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Published: 2026-10-05
Score: 6 Medium
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Avoid untrusted builds. Rootless mode mitigates device access but not denial of service.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Moby
Moby buildkit
Vendors & Products Moby
Moby buildkit

Mon, 05 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 05 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Title BuildKit improperly handles special files in build snapshots
Weaknesses CWE-441
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Docker

Published:

Updated: 2026-10-05T18:52:25.223Z

Reserved: 2026-09-17T17:18:00.217Z

Link: CVE-2026-93320

cve-icon Vulnrichment

Updated: 2026-10-05T18:52:16.741Z

cve-icon NVD

Status : Received

Published: 2026-10-05T18:17:38.353

Modified: 2026-10-05T19:17:26.177

Link: CVE-2026-93320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T21:00:18Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')