Back

CRITICAL

BuildKit possible host system access from mount stub cleaner

Published Jan 31, 2024

Description

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit frontend or Dockerfile using RUN --mount could trick the feature that removes empty files created for the mountpoints into removing a file outside the container, from the host system. The issue has been fixed in v0.12.5. Workarounds include avoiding using BuildKit frontends from an untrusted source or building an untrusted Dockerfile containing RUN --mount feature.

Affected products

Remediation

Red Hat statement

The following are preconditions for exploiting this vulnerability: * A container is built using a Dockerfile OR * A BuildKit frontend is invoked with the RUN --mount command Additionally, for the cleanup operations to impact the host file system the parent of the target directory needs to be replaced with a symbolic link during the build container's lifetime. For these reasons, this flaw was rated with an important severity.

Weaknesses (1)

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jan 31, 2024
Updated Jun 17, 2025
Reserved Jan 19, 2024
CISA Vulnrichment
Updated Feb 1, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 31, 2024
ENISA EUVD
Assigner n/a
Published n/a
Updated n/a
Exploited since n/a
Link n/a
GHSA-4V98-7QMW-RQR8