Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Only build from trusted build contexts. Run buildkitd under a memory limit (cgroup or container limit) so exhaustion is contained to the daemon.
Mon, 05 Oct 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moby
Moby buildkit |
|
| Vendors & Products |
Moby
Moby buildkit |
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB. | |
| Title | Oversized Dockerfile or .dockerignore can exhaust buildkitd memory | |
| Weaknesses | CWE-789 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-05T18:47:42.179Z
Reserved: 2026-09-17T17:18:17.963Z
Link: CVE-2026-93323
Updated: 2026-10-05T18:47:29.202Z
Status : Received
Published: 2026-10-05T18:17:39.630
Modified: 2026-10-05T19:17:26.403
Link: CVE-2026-93323
No data.
OpenCVE Enrichment
Updated: 2026-10-05T22:00:10Z