Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0383 | BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition that can lead to files from the host system being accessible to the build container. The issue has been fixed in v0.12.5. Workarounds include, avoiding using BuildKit frontend from an untrusted source or building an untrusted Dockerfile containing cache mounts with --mount=type=cache,source=... options. |
Github GHSA |
GHSA-m3r6-h7wv-7xxv | BuildKit vulnerable to possible race condition with accessing subpaths from cache mounts |
Ubuntu USN |
USN-7474-1 | Docker vulnerabilities |
Thu, 29 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-05-29T15:03:12.436Z
Reserved: 2024-01-19T00:18:53.234Z
Link: CVE-2024-23651
Updated: 2024-08-01T23:06:25.341Z
Status : Modified
Published: 2024-01-31T22:15:54.183
Modified: 2024-11-21T08:58:05.560
Link: CVE-2024-23651
OpenCVE Enrichment
No data.
EUVD
Github GHSA
Ubuntu USN