Medium [CVE-2026-75593] File escape vulnerability allows unauthorized file modification
This medium-severity Red Hat Linux advisory covers CVE-2026-75593 affecting Assisted Installer for Red Hat OpenShift Container Platform 2, Compliance Operator, Confidential Compute Attestation.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom client can produce such an upload request to the BuildKit daemon that files can escape from the BuildKit-controlled state directory.
The client needs to have valid permissions to access BuildKit control API to issue builds, eg., bypass authentication, etc. This issue is fixed in version 0.31.2.
This request allows files to escape from the BuildKit-controlled state directory, potentially leading to unauthorized modification or deletion of files on the system. A flaw in BuildKit allows a client with valid permissions to the BuildKit control API to perform unauthorized file modifications outside the intended build state directory.
This issue is limited to authenticated clients, reducing the overall attack surface. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).
Weakness: CWE-22.
Affected products named by the advisory: Assisted Installer for Red Hat OpenShift Container Platform 2; Compliance Operator; Confidential Compute Attestation; Kernel Module Management Operator for Red Hat Openshift; and 33 more.
- < 0.31.2
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Mitigation checklist
- Restrict access to the BuildKit control API to only trusted users and services. Implement robust authentication and authorization policies for all clients interacting with the BuildKit daemon to prevent unauthorized access and potential file system escapes.
Official advisory · high-confidence parse· fetched 1 hour ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.