Security update for docker-stable
This security update for docker-stable addresses two vulnerabilities in the BuildKit component. The first (CVE-2026-33747) involves malicious frontends crafting API messages that cause files to be written outside the BuildKit state directory. The second (CVE-2026-33748) concerns insufficient validation of Git URL fragment subdirectory components, potentially allowing access to files outside the checked-out Git repository. Both issues have been fixed in this update.
AI Analysis
Technical Summary
The update for docker-stable fixes two security issues in the BuildKit component. CVE-2026-33747 allows malicious frontends to craft API messages that result in file writes outside the BuildKit state directory, potentially leading to unauthorized file modifications. CVE-2026-33748 involves insufficient validation of Git URL fragment subdirectory components, which may allow attackers to access files outside the intended Git repository checkout. These vulnerabilities were identified and addressed by the SUSE Product Security Team in the docker-stable-24.0.9_ce-160000.5.1.aarch64 and docker-stable-buildx-0.25.0-160000.5.1.aarch64 packages.
Potential Impact
Exploitation of CVE-2026-33747 could allow an attacker controlling a malicious frontend to write files outside the BuildKit state directory, potentially leading to unauthorized file system modifications. CVE-2026-33748 could allow an attacker to access files outside the checked-out Git repository due to insufficient validation of Git URL fragments, potentially exposing sensitive information. Both vulnerabilities pose a high security risk if exploited.
Mitigation Recommendations
This security update fixes the described vulnerabilities. Users should apply the update to docker-stable packages docker-stable-24.0.9_ce-160000.5.1.aarch64 and docker-stable-buildx-0.25.0-160000.5.1.aarch64 provided by SUSE. No additional mitigations are specified beyond applying this official fix.
Security update for docker-stable
Description
This security update for docker-stable addresses two vulnerabilities in the BuildKit component. The first (CVE-2026-33747) involves malicious frontends crafting API messages that cause files to be written outside the BuildKit state directory. The second (CVE-2026-33748) concerns insufficient validation of Git URL fragment subdirectory components, potentially allowing access to files outside the checked-out Git repository. Both issues have been fixed in this update.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The update for docker-stable fixes two security issues in the BuildKit component. CVE-2026-33747 allows malicious frontends to craft API messages that result in file writes outside the BuildKit state directory, potentially leading to unauthorized file modifications. CVE-2026-33748 involves insufficient validation of Git URL fragment subdirectory components, which may allow attackers to access files outside the intended Git repository checkout. These vulnerabilities were identified and addressed by the SUSE Product Security Team in the docker-stable-24.0.9_ce-160000.5.1.aarch64 and docker-stable-buildx-0.25.0-160000.5.1.aarch64 packages.
Potential Impact
Exploitation of CVE-2026-33747 could allow an attacker controlling a malicious frontend to write files outside the BuildKit state directory, potentially leading to unauthorized file system modifications. CVE-2026-33748 could allow an attacker to access files outside the checked-out Git repository due to insufficient validation of Git URL fragments, potentially exposing sensitive information. Both vulnerabilities pose a high security risk if exploited.
Mitigation Recommendations
This security update fixes the described vulnerabilities. Users should apply the update to docker-stable packages docker-stable-24.0.9_ce-160000.5.1.aarch64 and docker-stable-buildx-0.25.0-160000.5.1.aarch64 provided by SUSE. No additional mitigations are specified beyond applying this official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- SUSE-SU-2026:2578-1
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-33748","CVE-2026-33997","CVE-2026-34040"]
- State
- PUBLISHED
Threat ID: 6a3c0d28eed863c81e23f2f1
Added to database: 06/24/2026, 17:00:24 UTC
Last enriched: 09/17/2026, 03:25:26 UTC
Last updated: 09/22/2026, 01:52:43 UTC
Views: 121
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.