CVE-2026-61711
ADVISORY - githubSummary
Impact
A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers.
Patches
Problem has been fixed in versions v0.31.1+
Workarounds
Only use BuildKit frontends from trusted providers.
NIST
-
CVSS SCORE
5.3mediumGitHub
-
CVSS SCORE
5.3mediumChainguard
CGA-7w6w-pqpr-3rhw
-
minimos
MINI-2vjx-26f4-3mc8
-
minimos
MINI-33pc-466v-76wj
-
minimos
MINI-3ffh-9rjm-j5r3
-
minimos
MINI-3m85-8fq7-jrwv
-
minimos
MINI-3mf4-mw3q-3jg7
-
minimos
MINI-5f9f-w5f4-w6p4
-
minimos
MINI-7vjw-3fff-rpr5
-
minimos
MINI-82fr-gw73-rwxf
-
minimos
MINI-8773-69vg-484m
-
minimos
MINI-8j7w-9mrg-3795
-
minimos
MINI-fh7f-8cmw-h3h9
-
minimos
MINI-ggj7-r4rx-vpcw
-
minimos
MINI-grgx-9mqm-p4pj
-
minimos
MINI-h67m-w84w-p53w
-
minimos
MINI-h6rp-7r2h-jgjc
-
minimos
MINI-h7x9-j657-5cwr
-
minimos
MINI-hv6c-jj5v-6xgw
-
minimos
MINI-m24f-hx84-rc7j
-
minimos
MINI-m9cv-vp7h-2g5v
-
minimos
MINI-mmj9-j2xg-4w68
-
minimos
MINI-p7hq-frcf-2m4q
-
minimos
MINI-q6xp-j8g3-h29w
-
minimos
MINI-vgrh-33r6-wfvj
-
minimos
MINI-w7wx-jc39-6vmj
-