CVE-2026-93321: Malformed LLB file operation can crash buildkitd
Published Oct 5, 2026
·Updated
A malicious frontend can submit an LLB definition that causes buildkitd to panic and terminate, interrupting all builds running on that daemon.
Affected Software
1 affected component
Docker BuildKit
Event History
Oct 5, 2026
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to trigger the issue?
An attacker needs to operate a malicious frontend that can submit an LLB definition to the BuildKit daemon. The supplied CVSS vector indicates no privileges or user interaction are required, but the attack vector is local.
2
Which systems are most exposed?
BuildKit daemons that process LLB definitions from untrusted or insufficiently trusted frontends are exposed. A successful attack terminates the daemon and interrupts every build running on that daemon.
3
How might an active attack appear operationally?
The primary observable symptom is buildkitd panicking and terminating, accompanied by simultaneous interruption of builds running on that daemon.