#1150158 docker-buildx: CVE-2026-103433

Package:
src:docker-buildx
Source:
src:docker-buildx
Submitter:
Salvatore Bonaccorso
Date:
2026-10-06 09:59:04 UTC
Severity:
normal
Tags:
#1150158#5
Date:
2026-10-06 09:57:46 UTC
From:
To:
Hi,

The following vulnerability was published for docker-buildx.

CVE-2026-103433[0]:
| Docker Buildx Bake does not request the expected fs.read approval
| for certain filesystem inputs. An untrusted Bake definition can
| expose a readable file through a pathless secret whose ID is
| interpreted as a client-side pathname, or consume a local OCI image
| layout outside the project after entitlement validation checks a
| different path representation. Users who run untrusted Bake
| definitions are affected.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-103433
https://www.cve.org/CVERecord?id=CVE-2026-103433
[1] https://github.com/docker/buildx/security/advisories/GHSA-p54p-jq4x-rc28

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore