Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Only build from trusted build contexts. Run buildkitd under a memory limit (cgroup or container limit) so exhaustion is contained to the daemon.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB. | |
| Title | Oversized Dockerfile or .dockerignore can exhaust buildkitd memory | |
| Weaknesses | CWE-789 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-05T18:47:42.179Z
Reserved: 2026-09-17T17:18:17.963Z
Link: CVE-2026-93323
Updated: 2026-10-05T18:47:29.202Z
Status : Received
Published: 2026-10-05T18:17:39.630
Modified: 2026-10-05T19:17:26.403
Link: CVE-2026-93323
No data.
OpenCVE Enrichment
No data.
-
CWE-789
Memory Allocation with Excessive Size Value