CVE-2026-93320

moby BuildKit

Published 5 Oct 2026 · updated 5 Oct 2026 · Received

6.0 Medium · CVSS 4.0, docker.com

Description

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

References