Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
The issue only appears when --cdi-disabled is set as a specific flag in daemon startup or TOML config. Without it, builds get regular entitlement checks and fail cleanly if the user doesn't allow specific CDI entitlements per build.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 05 Oct 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | If BuildKit daemon is started with --cdi-disabled it can lead to daemon panic when builds try to use CDI devices. This can happen maliciously or by accident. | |
| Title | Starting daemon with --cdi-disabled flag can lead to panic on specific builds | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Docker
Published:
Updated: 2026-10-05T17:42:12.969Z
Reserved: 2026-09-17T17:17:35.128Z
Link: CVE-2026-93316
No data.
No data.
No data.
OpenCVE Enrichment
No data.