openSUSE-SU-2026:20814-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20814-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:20814-1
Upstream
CVE (2)
Related
Published
2026-05-26T12:21:52Z
Modified
2026-05-29T18:24:10Z
Summary
Security update for docker-stable
Details

This update for docker-stable fixes the following issues

  • CVE-2026-33747: github.com/moby/buildkit: malicious frontends can craft API messages that cause files to be written outside of the BuildKit state directory (bsc#1260967).
  • CVE-2026-33748: github.com/moby/buildkit: insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository (bsc#1261078).
References

Affected packages