AZL-106746

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106746.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106746
Upstream
Published
2026-10-05T18:17:39Z
Modified
2026-10-10T05:36:40Z
Summary
CVE-2026-93323 affecting package docker-buildx 0.14.0-17
Details

The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.

References

Affected packages

Azure Linux:3 / docker-buildx

Package

Name
docker-buildx
Purl
pkg:rpm/azure-linux/docker-buildx

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.14.0-17

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106746.json"