PT-2024-1518 · Buildkit+2 · Buildkit+2

Rmcnamara-Snyk

·

Published

2024-01-31

·

Updated

2026-05-18

·

CVE-2024-23653

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions BuildKit versions prior to 0.12.5
Description The issue is related to improper authorization in BuildKit, allowing a remote attacker to run containers with elevated privileges. BuildKit provides APIs for running interactive containers based on built images, and it was possible to use these APIs to ask BuildKit to run a container with elevated privileges. Normally, running such containers is only allowed if special security.insecure entitlement is enabled both by buildkitd configuration and allowed by the user initializing the build request.
Recommendations For versions prior to 0.12.5, update to version 0.12.5 or later to fix the issue. As a temporary workaround, consider avoiding the use of BuildKit frontends from untrusted sources. Restrict access to the security.insecure entitlement to minimize the risk of exploitation. Avoid using the APIs for running interactive containers based on built images until the issue is resolved.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-34078
AZL-34079
AZL-34081
AZL-34084
AZL-34998
AZL-35433
AZL-35439
BDU:2024-01030
CLEANSTART-2026-BK59402
CLEANSTART-2026-BN11148
CLEANSTART-2026-GY69323
CLEANSTART-2026-HI89495
CLEANSTART-2026-HL71566
CLEANSTART-2026-JD48541
CLEANSTART-2026-OS18490
CLEANSTART-2026-SB85645
CLEANSTART-2026-SP51034
CLEANSTART-2026-TD34476
CLEANSTART-2026-XL45869
CLEANSTART-2026-YB44027
CLEANSTART-2026-ZM20570
CVE-2024-23653
GHSA-WR6V-9F75-VH2G
GO-2024-2497
OPENSUSE-SU-2024:13688-1
OPENSUSE-SU-2024:13689-1
OPENSUSE-SU-2024:14059-1
OPENSUSE-SU-2024:14571-1
OPENSUSE-SU-2024_3120-1
OPENSUSE-SU-2025_0226-1
SUSE-RU-2024:4391-1
SUSE-SU-2024:0586-1
SUSE-SU-2024:0586-2
SUSE-SU-2024:0587-1
SUSE-SU-2024:1469-1
SUSE-SU-2024:3120-1
SUSE-SU-2025:0226-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1
SUSE-SU-2025:1102-1
SUSE-SU-2025:20056-1
SUSE-SU-2025:20107-1
SUSE-SU-2025_0226-1

Affected Products

Astra Linux
Buildkit
Suse