CVE-2026-93323: Oversized Dockerfile or .dockerignore can exhaust buildkitd memory

Published Oct 5, 2026
·
Updated

The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.

Affected Software

1 affected component
Docker BuildKit

Event History

Oct 5, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can trigger the memory exhaustion condition?

Any party able to submit or control a build context can include an oversized Dockerfile or .dockerignore file. The resulting build can exhaust buildkitd memory and interrupt other builds handled by the same daemon.

2

What configuration or file size is affected?

The affected behavior occurs when the Dockerfile frontend loads Dockerfile or .dockerignore content without a size limit. The fix rejects these files when they exceed 16 MiB.

3

How can I check whether a build may have caused this issue?

Review build contexts for Dockerfile or .dockerignore files larger than 16 MiB and check whether buildkitd terminated or other builds were interrupted during processing. The described impact is memory consumption proportional to the oversized file.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203