Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97032.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-97032
Upstream
Published
2026-08-19T20:17:19Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-61711 affecting package moby-engine 25.0.3-19
Details

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.1, a custom frontend could place an invalid SecurityMode value in a crafted build request, and executor/oci/spec_linux.go treated the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement. This disabled Seccomp and AppArmor protections for the build container even though Linux capabilities remained restricted. This issue is fixed in version 0.31.1.

References

Affected packages

Azure Linux:3 / moby-engine

Package

Name
moby-engine
Purl
pkg:rpm/azure-linux/moby-engine

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
25.0.3-19

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-97032.json"