GHSA-72x6-4j93-7w86Low
BuildKit has a possible runtime DoS via unbounded group parsing
🔗 CVE IDs covered (1)
📋 Description
Impact
Maliciously crafted base image or build can cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the buildkitd process.
Patches
Issue is fixed in BuildKit v0.31.1+
Workarounds
Use trusted build sources.
References
This is BuildKit variant of containerd advisory https://github.com/containerd/containerd/security/advisories/GHSA-jpcc-p29g-p8mq
🎯 Affected products1
- go/github.com/moby/buildkit:<= 0.31.0
🔗 References (5)
- https://github.com/moby/buildkit/security/advisories/GHSA-72x6-4j93-7w86
- https://github.com/moby/buildkit/commit/408266e4ba254cecabedaacdad6905de4d2a75a1
- https://github.com/moby/buildkit/commit/69a3924648e485acb3faad3081e03a8554431255
- https://github.com/moby/buildkit/releases/tag/v0.31.1
- https://github.com/advisories/GHSA-72x6-4j93-7w86