What is CVE-2026-61712?
CVE-2026-61712 is a vulnerability in BuildKit where it reads attacker-controlled /etc/passwd and /etc/group files without an upper bound while resolving user or group identifiers. This affects BuildKit versions prior to 0.31.1. Upgrading to version 0.31.1 is recommended.
Azərbaycanca: CVE-2026-61712 - BuildKit-də istifadəçi və ya qrup identifikatorlarını həll edərkən hücumçunun nəzarət etdiyi /etc/passwd və /etc/group fayllarını məhdudiyyətsiz oxuma zəifliyidir. Bu, BuildKit-in 0.31.1-dən əvvəlki versiyalarına təsir edir. BuildKit-i 0.31.1 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
During which BuildKit operation does the CVE-2026-61712 vulnerability occur?
The vulnerability occurs when BuildKit resolves user or group identifiers.
To which version is it recommended to upgrade to mitigate CVE-2026-61712?
It is recommended to upgrade BuildKit to version 0.31.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.