PT-2026-28525 · Buildkit+3 · Buildkit+3

·

CVE-2026-33747

·

Publicado

2026-03-26

·

Atualizado

2026-06-23

CVSS v2.0

10

Crítica

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BuildKit versions prior to 0.28.1
Description BuildKit is a toolkit for converting source code to build artifacts. When using a custom BuildKit frontend, a malicious frontend can craft an API message that causes files to be written outside of the BuildKit state directory for the execution context. This issue requires using an untrusted BuildKit frontend set with #syntax or --build-arg BUILDKIT SYNTAX. Using these options with a well-known frontend image like docker/dockerfile is not affected. The API message crafted by the frontend can lead to file escape outside of the storage root.
Recommendations Versions prior to 0.28.1 should be updated to version 0.28.1 or later.

Exploit

Correção

DoS

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-07149
CLEANSTART-2026-FK40318
CVE-2026-33747
GHSA-4C29-8RGM-JVJJ
GO-2026-4858
OPENSUSE-SU-2026:10456-1
OPENSUSE-SU-2026:10472-1
OPENSUSE-SU-2026:10651-1
OPENSUSE-SU-2026:11075-1
OPENSUSE-SU-2026:20702-1
OPENSUSE-SU-2026:20809-1
OPENSUSE-SU-2026:20814-1
SUSE-SU-2026:1205-1
SUSE-SU-2026:2120-1
SUSE-SU-2026:21851-1
SUSE-SU-2026:2578-1
USN-8230-1

Produtos afetados

Buildkit
Linuxmint
Red Os
Ubuntu