CVE-2026-93316: Starting daemon with --cdi-disabled flag can lead to panic on specific builds
Published Oct 5, 2026
·Updated
If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident.
Affected Software
1 affected component
Docker BuildKit
Event History
Oct 5, 2026
CVE Published
via MITRE·05:42 PM
Data Sourced
via MITRE·05:42 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What configuration is required for this issue to occur?
The BuildKit daemon must be started with the --cdi-disabled flag, and a build must attempt to use CDI devices.
2
Can this be triggered unintentionally?
Yes. A build attempting to use CDI devices can trigger the daemon panic either maliciously or accidentally.
3
What is the operational impact of successful triggering?
The BuildKit daemon can panic, interrupting its operation.