[Git][security-tracker-team/security-tracker][master] Add new buildkit issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 22 07:54:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f41988aa by Salvatore Bonaccorso at 2026-08-22T08:53:52+02:00
Add new buildkit issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1834,7 +1834,9 @@ CVE-2026-75595 (Netty is an asynchronous, event-driven network application frame
 	NOTE: https://github.com/netty/netty/pull/17217
 	NOTE: Fixed by: https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961 (netty-4.1.137.Final)
 CVE-2026-75593 (BuildKit is a toolkit for converting source code to build artifacts in ...)
-	TODO: check
+	- golang-github-moby-buildkit <itp> (bug #1094971)
+	NOTE: https://github.com/moby/buildkit/security/advisories/GHSA-g2h8-426c-7976
+	TODO: check security impact on docker.io
 CVE-2026-75569 (A flaw was found in mce-operator-bundle. The build process fetches and ...)
 	NOT-FOR-US: mce-operator-bundle
 CVE-2026-75476 (Tanium addressed a compression bomb vulnerability in Threat Response.)
@@ -1903,9 +1905,17 @@ CVE-2026-62727 (Concurrent execution using shared resource with improper synchro
 CVE-2026-62317 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
 	NOT-FOR-US: Logto
 CVE-2026-61712 (BuildKit is a toolkit for converting source code to build artifacts in ...)
-	TODO: check
+	- golang-github-moby-buildkit <itp> (bug #1094971)
+	NOTE: https://github.com/moby/buildkit/security/advisories/GHSA-72x6-4j93-7w86
+	NOTE: Fixed by: https://github.com/moby/buildkit/commit/69a3924648e485acb3faad3081e03a8554431255 (v0.31.1)
+	NOTE: Fixed by: https://github.com/moby/buildkit/commit/408266e4ba254cecabedaacdad6905de4d2a75a1 (v0.32.0-rc1)
+	TODO: check potential security impact on docker.io
 CVE-2026-61711 (BuildKit is a toolkit for converting source code to build artifacts in ...)
-	TODO: check
+	- golang-github-moby-buildkit <itp> (bug #1094971)
+	NOTE: https://github.com/moby/buildkit/security/advisories/GHSA-7236-3392-c5c6
+	NOTE: Fixed by: https://github.com/moby/buildkit/commit/3ea6dd0ce7d269cdb8aa23348718e2c1bf64f109 (v0.31.1)
+	NOTE: Fixed by: https://github.com/moby/buildkit/commit/64bbec89ca43dd95b2853edeca240c33c6729910 (v0.32.0-rc1)
+	TODO: check security impact on docker.io
 CVE-2026-61556 (LiquidJS is a Shopify / GitHub Pages compatible template engine in pur ...)
 	NOT-FOR-US: LiquidJS
 CVE-2026-59992 (Tina is a headless content management system. Prior to next-tinacms-s3 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f41988aa876b3d530227804ef2858b4b00f29209

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f41988aa876b3d530227804ef2858b4b00f29209
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/0c71f4aa/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list