
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-61711 is a security feature bypass vulnerability in Moby BuildKit, a toolkit for converting source code to build artifacts. A custom frontend could place an invalid SecurityMode value in a crafted build request, causing executor/oci/spec_linux.go to treat the unsupported value as a non-sandbox mode without requiring the security.insecure entitlement — thereby disabling Seccomp and AppArmor protections for the build container. All versions up to and including v0.31.0 are affected; the issue was fixed in v0.31.1. It carries a CVSS v4.0 base score of 5.3 (Moderate/Medium) (Github Advisory, BuildKit Release).
The root cause is improper input validation (CWE-20) in the generateSecurityOpts function within executor/oci/spec_linux.go. Prior to the fix, the function used a switch statement that only explicitly handled SecurityMode_INSECURE and SecurityMode_SANDBOX; any other integer value fell through without applying sandbox security options (Seccomp and AppArmor), effectively treating it as an insecure mode without checking for the security.insecure entitlement. An attacker with the ability to submit a custom frontend build request over the network (with low privileges) could craft a build request setting SecurityMode to an invalid enum value (e.g., pb.SecurityMode(2)) to trigger this path. The fix introduced a ValidateSecurityMode() function in solver/pb/securitymode.go that rejects any value other than SecurityMode_SANDBOX or SecurityMode_INSECURE, applied consistently across all platform-specific spec files (Github Advisory, Fix Commit).
Successful exploitation reduces the isolation of the affected build container by disabling Seccomp and AppArmor kernel security profiles, allowing the container to perform syscalls or operations that would otherwise be blocked by those profiles. Notably, Linux capabilities remain restricted, limiting the severity of the bypass. An attacker exploiting this vulnerability could potentially execute restricted syscalls within the build container, access sensitive information, or perform unauthorized operations that the Seccomp/AppArmor profiles were designed to prevent — though full container escape is not directly implied (Github Advisory, Feedly).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.357% (29th percentile), indicating a low probability of exploitation in the near term. Exploitation requires low-level privileges (ability to submit custom frontend build requests to a BuildKit instance) and is not automatable according to NVD SSVC assessment.
SecurityMode field in an ExecOp or StartRequest to an invalid integer value not defined in the SecurityMode enum (e.g., pb.SecurityMode(2)).generateSecurityOpts in spec_linux.go falls through without applying Seccomp or AppArmor profiles.SecurityMode values; absence of Seccomp-related log entries for containers that should have sandbox protections applied./proc/self/status shows Seccomp: 0 (Seccomp disabled) despite not having the security.insecure entitlement explicitly granted.Upgrade BuildKit to version v0.31.1 or later, which introduces ValidateSecurityMode() validation that rejects any unknown SecurityMode values before generating executor specs (BuildKit Release). As a workaround for environments that cannot immediately upgrade, restrict the ability to submit custom frontend build requests to trusted users and trusted frontend images only (Github Advisory). Additionally, consider implementing supplementary runtime security controls (e.g., host-level Seccomp policies or mandatory access control) to compensate for the weakened container isolation until patching is complete.
The vulnerability was reported by security researcher Alex0Young and fixed by BuildKit maintainer Tõnis Tiigi. It was released as part of a security patch release (v0.31.1) that also addressed a separate low-severity runtime DoS issue (GHSA-72x6-4j93-7w86). The advisory was rated "Low" severity by the maintainers in the repository advisory, though the GitHub Advisory Database classifies it as "Moderate" based on the CVSS v4.0 score of 5.3 (Github Advisory, BuildKit Release).
主要なLinuxディストリビューションおよびそのリリースにおける修正の提供状況。
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"