{"id":"GO-2024-2492","summary":"Panic in github.com/moby/buildkit","details":"A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic.","aliases":["CVE-2024-23650","GHSA-9p26-698r-w4hx"],"modified":"2026-02-04T04:01:30.810252Z","published":"2024-02-12T18:45:38Z","related":["CGA-v4qr-xpwq-274m"],"database_specific":{"review_status":"REVIEWED","url":"https://pkg.go.dev/vuln/GO-2024-2492"},"references":[{"type":"FIX","url":"https://github.com/moby/buildkit/pull/4601"},{"type":"FIX","url":"https://github.com/moby/buildkit/commit/e1924dc32da35bfb0bfdbb9d0fc7bca25e552330"},{"type":"FIX","url":"https://github.com/moby/buildkit/commit/7718bd5c3dc8fc5cd246a30cc41766e7a53c043c"},{"type":"FIX","url":"https://github.com/moby/buildkit/commit/96663dd35bf3787d7efb1ee7fd9ac7fe533582ae"},{"type":"FIX","url":"https://github.com/moby/buildkit/commit/481d9c45f473c58537f39694a38d7995cc656987"},{"type":"FIX","url":"https://github.com/moby/buildkit/commit/83edaef59d545b93e2750f1f85675a3764593fee"},{"type":"WEB","url":"https://github.com/moby/buildkit/releases/tag/v0.12.5"}],"affected":[{"package":{"name":"github.com/moby/buildkit","ecosystem":"Go","purl":"pkg:golang/github.com/moby/buildkit"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.12.5"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/moby/buildkit/solver/llbsolver","symbols":["Solver.Solve","llbBridge.loadResult","loadSourcePolicy"]},{"path":"github.com/moby/buildkit/sourcepolicy","symbols":["match"]},{"path":"github.com/moby/buildkit/control","symbols":["Controller.Solve"]},{"path":"github.com/moby/buildkit/frontend/gateway/client","symbols":["AttestationFromPB"]},{"path":"github.com/moby/buildkit/frontend/gateway","symbols":["llbBridgeForwarder.Solve","llbBridgeForwarder.Warn"]},{"path":"github.com/moby/buildkit/util/tracing/transform","symbols":["Attributes","Spans","arrayValues","boolArray","doubleArray","intArray","links","spanEvents","statusCode","stringArray"]},{"path":"github.com/moby/buildkit/exporter/containerimage/exptypes","symbols":["ParsePlatforms"]},{"path":"github.com/moby/buildkit/exporter/containerimage","symbols":["patchImageConfig"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2024-2492.json"}}],"schema_version":"1.7.3","credits":[{"name":"@cpuguy83"}]}