CVE-2026-93316

NameCVE-2026-93316
DescriptionIf BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1094971

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-github-moby-buildkitITP1094971

Notes

https://github.com/moby/buildkit/security/advisories/GHSA-r456-g3gm-cvxf
check security impact on docker.io

Search for package or bug name: Reporting problems