PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-61712 moby CVE debrief

BuildKit is vulnerable to a denial-of-service attack due to reading attacker-controlled /etc/passwd and /etc/group files without an upper bound, potentially leading to out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1. Affected users should review their current BuildKit version and take steps to update it. The vulnerability could be exploited by a malicious base image or build. Users should prioritize updating to version 0.31.1 to mitigate potential memory exhaustion attacks. This requires coordination between operators, platform administrators, security teams, and vulnerability management teams to ensure that all affected systems are updated and that compensating controls are in place for exposed systems. The CVE record was published on 2026-08-19T20:17:19.730Z and has not been modified since then. The NVD entry is currently LOW.

Vendor
moby
Product
buildkit
CVSS
LOW 2.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-08-21
Advisory published
2026-08-19
Advisory updated
2026-08-21

Who should care

Users of BuildKit, especially those using versions prior to 0.31.1, should be aware of this vulnerability and take steps to mitigate it. This includes verifying their current BuildKit version and updating to 0.31.1 if necessary. Additionally, users should review compensating controls for exposed systems and monitor for potential memory exhaustion attacks. Security teams should review the current BuildKit version in use and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Vulnerability management teams should track exceptions, retest remediated assets, and close the item only after evidence is documented. Operators and platform administrators should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also check relevant monitoring, detection, and logs for exposed assets that need extra review. Asset inventory management teams should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should also review compensating controls for exposed systems while remediation is scheduled and verified. Overall, users should prioritize updating to version 0.31.1 to mitigate potential memory exhaustion attacks. This requires coordination between operators, platform administrators, security teams, and vulnerability management teams to ensure that all affected systems are updated and that compensating controls are in place for exposed systems. The vulnerability highlights the importance of maintaining up-to-date software and monitoring for potential security threats. Users should also consider implementing additional security measures, such as monitoring and detection systems, to help prevent and respond to potential attacks. By taking these steps, users can help protect their systems from potential memory exhaustion attacks and ensure the security of their BuildKit deployments. This vulnerability is a reminder of the importance of staying vigilant and proactive in maintaining the security of software deployments. Users should stay informed about potential security threats and take steps to stay

Technical summary

BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound, potentially leading to out-of-memory termination of the buildkitd process. This issue is fixed in version 0.31.1. The vulnerability could be exploited to cause denial-of-service attacks. Affected users should review their current BuildKit version and take steps to update it. The issue is related to memory safety and could be triggered by a malicious base image or build.

Defensive priority

BuildKit users should prioritize updating to version 0.31.1 to mitigate potential memory exhaustion attacks.

Recommended defensive actions

  • Update BuildKit to version 0.31.1 or later
  • Verify BuildKit version in use
  • Monitor for potential memory exhaustion attacks
  • Review compensating controls for exposed systems
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record indicates that BuildKit read attacker-controlled /etc/passwd and /etc/group files without an upper bound, potentially leading to out-of-memory termination of the buildkitd process. Users should verify their BuildKit version and update to 0.31.1 if necessary. This issue is related to memory safety and could be exploited to cause denial-of-service attacks. Affected users should review their current BuildKit version and take steps to update it. Additionally, users should monitor for potential memory exhaustion attacks and review compensating controls for exposed systems.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T20:17:19.730Z and has not been modified since then.