UBUNTU-CVE-2024-23650

Source
https://ubuntu.com/security/CVE-2024-23650
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-23650.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2024-23650
Related
Published
2024-01-31T22:15:00Z
Modified
2025-04-23T15:16:32Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic. The issue has been fixed in v0.12.5. As a workaround, avoid using BuildKit frontends from untrusted sources.

References

Affected packages

Ubuntu:20.04:LTS / docker.io-app

Package

Name
docker.io-app
Purl
pkg:deb/ubuntu/docker.io-app@26.1.3-0ubuntu1~20.04.1?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20.*

20.10.25-0ubuntu1~20.04.1
20.10.25-0ubuntu1~20.04.2

24.*

24.0.5-0ubuntu1~20.04.1
24.0.7-0ubuntu2~20.04.1

26.*

26.1.3-0ubuntu1~20.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / docker.io-app

Package

Name
docker.io-app
Purl
pkg:deb/ubuntu/docker.io-app@26.1.3-0ubuntu1~22.04.1?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20.*

20.10.25-0ubuntu1~22.04.1
20.10.25-0ubuntu1~22.04.2

24.*

24.0.5-0ubuntu1~22.04.1
24.0.7-0ubuntu2~22.04.1

26.*

26.1.3-0ubuntu1~22.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / docker.io

Package

Name
docker.io
Purl
pkg:deb/ubuntu/docker.io@26.1.4+dfsg2-1ubuntu1.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

20.*

20.10.25+dfsg1-2ubuntu1
20.10.25+dfsg1-3ubuntu1

26.*

26.1.4+dfsg2-1ubuntu1
26.1.4+dfsg2-1ubuntu1.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / docker.io-app

Package

Name
docker.io-app
Purl
pkg:deb/ubuntu/docker.io-app@26.1.3-0ubuntu1.1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

24.*

24.0.7-0ubuntu4

26.*

26.1.3-0ubuntu1
26.1.3-0ubuntu1.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / docker.io-app

Package

Name
docker.io-app
Purl
pkg:deb/ubuntu/docker.io-app@26.1.3-0ubuntu1~24.04.1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

24.*

24.0.5-0ubuntu1
24.0.7-0ubuntu1
24.0.7-0ubuntu2
24.0.7-0ubuntu3
24.0.7-0ubuntu4
24.0.7-0ubuntu4.1

26.*

26.1.3-0ubuntu1~24.04.1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:25.04 / docker.io

Package

Name
docker.io
Purl
pkg:deb/ubuntu/docker.io@26.1.5+dfsg1-9ubuntu1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

26.*

26.1.4+dfsg2-1ubuntu1
26.1.5+dfsg1-4ubuntu1
26.1.5+dfsg1-7ubuntu1
26.1.5+dfsg1-9ubuntu1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:25.04 / docker.io-app

Package

Name
docker.io-app
Purl
pkg:deb/ubuntu/docker.io-app@27.5.1-0ubuntu3?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

26.*

26.1.3-0ubuntu1
26.1.3-0ubuntu2

27.*

27.5.1-0ubuntu3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}