AZL-106806

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106806.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106806
Upstream
Published
2026-10-05T18:17:38Z
Modified
2026-10-10T05:36:40Z
Summary
CVE-2026-93320 affecting package moby-engine 25.0.3-20
Details

BuildKit may be tricked into performing file actions with special file inodes where regular files are expected. Special files may block operations or, on rootful workers, allow unintended host device access.

References

Affected packages

Azure Linux:3 / moby-engine

Package

Name
moby-engine
Purl
pkg:rpm/azure-linux/moby-engine

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
25.0.3-20

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106806.json"