AZL-106824

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106824.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106824
Upstream
Published
2026-10-05T18:17:39Z
Modified
2026-10-10T05:36:40Z
Summary
CVE-2026-93323 affecting package moby-engine 25.0.3-20
Details

The Dockerfile frontend loaded the Dockerfile and .dockerignore files of a build context into memory without a size limit. A build context containing an oversized file could make buildkitd allocate memory proportional to that file, potentially exhausting memory and terminating the daemon, which interrupts other builds on the same instance. Fixed by rejecting such files above 16 MiB.

References

Affected packages

Azure Linux:3 / moby-engine

Package

Name
moby-engine
Purl
pkg:rpm/azure-linux/moby-engine

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
25.0.3-20

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106824.json"