1
+ {
2
+ "schema_version" : " 1.3.1" ,
3
+ "id" : " GO-2024-2492" ,
4
+ "modified" : " 0001-01-01T00:00:00Z" ,
5
+ "published" : " 0001-01-01T00:00:00Z" ,
6
+ "aliases" : [
7
+ " CVE-2024-23650" ,
8
+ " GHSA-9p26-698r-w4hx"
9
+ ],
10
+ "summary" : " Panic in github.com/moby/buildkit" ,
11
+ "details" : " A malicious BuildKit client or frontend could craft a request that could lead to a BuildKit daemon crashing with a panic." ,
12
+ "affected" : [
13
+ {
14
+ "package" : {
15
+ "name" : " github.com/moby/buildkit" ,
16
+ "ecosystem" : " Go"
17
+ },
18
+ "ranges" : [
19
+ {
20
+ "type" : " SEMVER" ,
21
+ "events" : [
22
+ {
23
+ "introduced" : " 0"
24
+ },
25
+ {
26
+ "fixed" : " 0.12.5"
27
+ }
28
+ ]
29
+ }
30
+ ],
31
+ "ecosystem_specific" : {
32
+ "imports" : [
33
+ {
34
+ "path" : " github.com/moby/buildkit/solver/llbsolver" ,
35
+ "symbols" : [
36
+ " Solver.Solve" ,
37
+ " llbBridge.loadResult" ,
38
+ " loadSourcePolicy"
39
+ ]
40
+ },
41
+ {
42
+ "path" : " github.com/moby/buildkit/sourcepolicy" ,
43
+ "symbols" : [
44
+ " match"
45
+ ]
46
+ },
47
+ {
48
+ "path" : " github.com/moby/buildkit/control" ,
49
+ "symbols" : [
50
+ " Controller.Solve"
51
+ ]
52
+ },
53
+ {
54
+ "path" : " github.com/moby/buildkit/frontend/gateway/client" ,
55
+ "symbols" : [
56
+ " AttestationFromPB"
57
+ ]
58
+ },
59
+ {
60
+ "path" : " github.com/moby/buildkit/frontend/gateway" ,
61
+ "symbols" : [
62
+ " llbBridgeForwarder.Solve" ,
63
+ " llbBridgeForwarder.Warn"
64
+ ]
65
+ },
66
+ {
67
+ "path" : " github.com/moby/buildkit/util/tracing/transform" ,
68
+ "symbols" : [
69
+ " Attributes" ,
70
+ " Spans" ,
71
+ " arrayValues" ,
72
+ " boolArray" ,
73
+ " doubleArray" ,
74
+ " intArray" ,
75
+ " links" ,
76
+ " spanEvents" ,
77
+ " statusCode" ,
78
+ " stringArray"
79
+ ]
80
+ },
81
+ {
82
+ "path" : " github.com/moby/buildkit/exporter/containerimage/exptypes" ,
83
+ "symbols" : [
84
+ " ParsePlatforms"
85
+ ]
86
+ },
87
+ {
88
+ "path" : " github.com/moby/buildkit/exporter/containerimage" ,
89
+ "symbols" : [
90
+ " patchImageConfig"
91
+ ]
92
+ }
93
+ ]
94
+ }
95
+ }
96
+ ],
97
+ "references" : [
98
+ {
99
+ "type" : " FIX" ,
100
+ "url" : " https://github.com/moby/buildkit/pull/4601"
101
+ },
102
+ {
103
+ "type" : " FIX" ,
104
+ "url" : " https://github.com/moby/buildkit/commit/e1924dc32da35bfb0bfdbb9d0fc7bca25e552330"
105
+ },
106
+ {
107
+ "type" : " FIX" ,
108
+ "url" : " https://github.com/moby/buildkit/commit/7718bd5c3dc8fc5cd246a30cc41766e7a53c043c"
109
+ },
110
+ {
111
+ "type" : " FIX" ,
112
+ "url" : " https://github.com/moby/buildkit/commit/96663dd35bf3787d7efb1ee7fd9ac7fe533582ae"
113
+ },
114
+ {
115
+ "type" : " FIX" ,
116
+ "url" : " https://github.com/moby/buildkit/commit/481d9c45f473c58537f39694a38d7995cc656987"
117
+ },
118
+ {
119
+ "type" : " FIX" ,
120
+ "url" : " https://github.com/moby/buildkit/commit/83edaef59d545b93e2750f1f85675a3764593fee"
121
+ },
122
+ {
123
+ "type" : " WEB" ,
124
+ "url" : " https://github.com/moby/buildkit/releases/tag/v0.12.5"
125
+ }
126
+ ],
127
+ "credits" : [
128
+ {
129
+ "name" : " @cpuguy83"
130
+ }
131
+ ],
132
+ "database_specific" : {
133
+ "url" : " https://pkg.go.dev/vuln/GO-2024-2492"
134
+ }
135
+ }
0 commit comments