Linuxsecurity
Critical Vulnerabilities in Fedora Docker-Buildx and Buildkit
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Fedora has released updates addressing critical vulnerabilities in docker-buildx and docker-buildkit. CVE-2026-39828 allows unauthorized command execution via discarded SSH permissions, while CVE-2026-39829 enables denial of service through crafted public keys. Both vulnerabilities were published on May 22, 2026, and affect users of Fedora 43 and 44. The updates, released on June 18, 2026, resolve these issues and include upstream enhancements. Users are advised to upgrade to the latest version using the 'dnf' update program. The vulnerabilities pose significant risks to system integrity and availability, necessitating immediate action from administrators.
Key Points: • CVE-2026-39828 allows unauthorized command execution in docker-buildx. • CVE-2026-39829 enables denial of service via crafted public keys in docker-buildkit. • Fedora users are urged to update to the latest versions immediately.