CVE-2026-33748
Publication date 22 April 2026
Last updated 6 May 2026
Ubuntu priority
Description
BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to version 0.28.1, insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository root. Possible access is limited to files on the same mounted filesystem. The issue has been fixed in version v0.28.1 The issue affects only builds that use Git URLs with a subpath component. As a workaround, avoid building Dockerfiles from untrusted sources or using the subdir component from an untrusted Git repository where the subdir component could point to a symlink.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| docker.io | 26.04 LTS resolute |
Vulnerable
|
| 25.10 questing |
Vulnerable
|
|
| 24.04 LTS noble |
Vulnerable
|
|
| 22.04 LTS jammy |
Vulnerable
|
|
| 20.04 LTS focal |
Vulnerable
|
|
| 18.04 LTS bionic |
Vulnerable
|
|
| 16.04 LTS xenial |
Vulnerable
|
|
| docker.io-app | 26.04 LTS resolute |
Fixed 29.1.3-0ubuntu4.1
|
| 25.10 questing |
Vulnerable
|
|
| 24.04 LTS noble |
Fixed 29.1.3-0ubuntu3~24.04.2
|
|
| 22.04 LTS jammy |
Fixed 29.1.3-0ubuntu3~22.04.2
|
|
| 20.04 LTS focal |
Fixed 26.1.3-0ubuntu1~20.04.1+esm2
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
alexmurray
Traditionally the docker.io source package contained both the library and docker application. However, in releases that contain the docker.io-app source package, the docker.io source package contains only the library whilst the docker application itself is contained in the docker.io-app package.
sbeattie
docker packages contain an embedded copy of github:moby/buildkit
Patch details
| Package | Patch details |
|---|---|
| docker.io | |
| docker.io-app |
References
Related Ubuntu Security Notices (USN)
- USN-8230-1
- Docker vulnerabilities
- 6 May 2026