Vulnerability Report: GO-2024-2492
- CVE-2024-23650, GHSA-9p26-698r-w4hx
- Affects: github.com/moby/buildkit
- Published: Feb 12, 2024
- Modified: May 20, 2024
A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.12.5
-
before v0.12.5
1 unexported affected symbols
- match
-
before v0.12.5
-
before v0.12.5
-
before v0.12.5
2 unexported affected symbols
- llbBridgeForwarder.Solve
- llbBridgeForwarder.Warn
-
before v0.12.5
-
before v0.12.5
-
before v0.12.5
1 unexported affected symbols
- patchImageConfig
Aliases
References
- https://github.com/moby/buildkit/pull/4601
- https://github.com/moby/buildkit/commit/e1924dc32da35bfb0bfdbb9d0fc7bca25e552330
- https://github.com/moby/buildkit/commit/7718bd5c3dc8fc5cd246a30cc41766e7a53c043c
- https://github.com/moby/buildkit/commit/96663dd35bf3787d7efb1ee7fd9ac7fe533582ae
- https://github.com/moby/buildkit/commit/481d9c45f473c58537f39694a38d7995cc656987
- https://github.com/moby/buildkit/commit/83edaef59d545b93e2750f1f85675a3764593fee
- https://github.com/moby/buildkit/releases/tag/v0.12.5
- https://vuln.go.dev/ID/GO-2024-2492.json
Credits
- @cpuguy83
Feedback
See anything missing or incorrect?
Suggest an edit to this report.