Security Advisories

Buildkit mount cache race

CVE-2024-23651

May 22, 2024

A critical vulnerability, CVE-2024-23651, has been identified in BuildKit <= v0.12.4, the vulnerability occurs when two malicious build steps running in parallel sharing the same cache mounts with subpaths could cause a race condition, leading to files from the host system being accessible to the build container.

Exploitation Status

At Aqua Security, we can reassure our customers and the wider community about the robustness of our security posture. A thorough review has confirmed that Aqua images are not susceptible to the vulnerabilities outlined. Although our images do incorporate runc libraries, these are categorized as indirect dependencies and thus do not present a vulnerability vector in our environment.