id: GO-ID-PENDING
modules:
- module: github.com/moby/buildkit
vulnerable_at: 0.12.5
packages:
- package: buildkit
cves:
- CVE-2024-23650
references:
- advisory: https://github.com/moby/buildkit/security/advisories/GHSA-9p26-698r-w4hx
- fix: https://github.com/moby/buildkit/pull/4601
- web: https://github.com/moby/buildkit/releases/tag/v0.12.5
CVE-2024-23650 references github.com/moby/buildkit, which may be a Go module.
Description:
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit frontends from untrusted sources.
References:
Cross references:
See doc/triage.md for instructions on how to triage this report.