CVE-2026-93323: Oversized Dockerfile or .dockerignore can exhaust buildkitd memory
The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.
Affected Software
Event History
Frequently Asked Questions
Who can trigger the memory exhaustion condition?
Any party able to submit or control a build context can include an oversized Dockerfile or .dockerignore file. The resulting build can exhaust buildkitd memory and interrupt other builds handled by the same daemon.
What configuration or file size is affected?
The affected behavior occurs when the Dockerfile frontend loads Dockerfile or .dockerignore content without a size limit. The fix rejects these files when they exceed 16 MiB.
How can I check whether a build may have caused this issue?
Review build contexts for Dockerfile or .dockerignore files larger than 16 MiB and check whether buildkitd terminated or other builds were interrupted during processing. The described impact is memory consumption proportional to the oversized file.