CVE-2026-93322

NameCVE-2026-93322
DescriptionA malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1094971

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
golang-github-moby-buildkitITP1094971

Notes

https://github.com/moby/buildkit/security/advisories/GHSA-cv6p-7w7g-xjwq
check security impact on docker.io

Search for package or bug name: Reporting problems