Loading HuntDB...

GHSA-m3r6-h7wv-7xxv

GitHub Security Advisory

BuildKit vulnerable to possible race condition with accessing subpaths from cache mounts

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact
Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container.

### Patches
The issue has been fixed in v0.12.5

### Workarounds
Avoid using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with `--mount=type=cache,source=...` options.

### References
https://www.openwall.com/lists/oss-security/2019/05/28/1

Affected Packages

Go github.com/moby/buildkit
Affected versions: 0 (fixed in 0.12.5)

Related CVEs

Key Information

GHSA ID
GHSA-m3r6-h7wv-7xxv
Published
January 31, 2024 10:43 PM
Last Modified
February 1, 2024 5:48 PM
CVSS Score
7.5 /10
Primary Ecosystem
Go
Primary Package
github.com/moby/buildkit
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 12, 2025 6:29 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.