Back

MEDIUM

BuildKit improperly handles special files in build snapshots

Published Oct 5, 2026

Description

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

Affected products

Remediation

Vendor solution

Avoid untrusted builds. Rootless mode mitigates device access but not denial of service.

Weaknesses (2)

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Docker
Published Oct 5, 2026
Updated Oct 5, 2026
Reserved Sep 17, 2026
CISA Vulnrichment
Updated Oct 5, 2026
NVD
Status Awaiting Analysis
Modified Oct 6, 2026
Red Hat
Severity Important
Public date Oct 5, 2026
ENISA EUVD
Assigner Docker
Published Oct 5, 2026
Updated Oct 5, 2026
Exploited since n/a
EUVD-2026-92539