MEDIUM
BuildKit improperly handles special files in build snapshots
Published Oct 5, 2026
6.0
MEDIUMCVSS 4.0
EPSS 0.11%
Description
BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.
Affected products
-
- Version 0StatusaffectedConstraints<=0.33.0
- Version
No data.
No data.
Red Hat Hardened Images
buildah
Affected
Red Hat Hardened Images
podman
Affected
Red Hat Hardened Images
trivy
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Hardened Images | buildah | Affected | n/a |
| Red Hat Hardened Images | podman | Affected | n/a |
| Red Hat Hardened Images | trivy | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Avoid untrusted builds. Rootless mode mitigates device access but not denial of service.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-93320 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2546036 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-92539 Advisory
- https://github.com/moby/buildkit/releases/tag/v0.33.1 patch
- https://github.com/moby/buildkit/security/advisories/GHSA-9728-qjrv-2xh2 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-93320
- https://www.cve.org/CVERecord?id=CVE-2026-93320
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Docker
Published Oct 5, 2026
Updated Oct 5, 2026
Reserved Sep 17, 2026
Link CVE-2026-93320
CISA Vulnrichment
Updated Oct 5, 2026
ENISA EUVD
EUVD-2026-92539 Assigner Docker
Published Oct 5, 2026
Updated Oct 5, 2026
Exploited since n/a
Link EUVD-2026-92539