CVE-2026-93317

NameCVE-2026-93317
DescriptionAn unauthenticated attacker controlling a registry or OCI-layout blob source could provide blob contents that did not match the claimed digest. The resulting snapshot could be cached under that digest and reused by a later victim build, compromising build-input integrity.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1094971

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-github-moby-buildkitITP1094971

Notes

ttps://github.com/moby/buildkit/security/advisories/GHSA-p3rc-w3hc-pqvv
check security impact on docker.io

Search for package or bug name: Reporting problems