Security update for docker-stable
This update for docker-stable fixes the following issues - CVE-2026-33747: github.com/moby/buildkit: malicious frontends can craft API messages that cause files to be written outside of the BuildKit state directory (bsc#1260967). - CVE-2026-33748: github.com/moby/buildkit: insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository (bsc#1261078). - CVE-2026-33997: Fixed privilege validation bypass during plugin (bsc#1265907). - CVE-2026-34040: Fixed Authz zero length regression (bsc#1265929).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for docker-stable fixes the following issues - CVE-2026-33747: github.com/moby/buildkit: malicious frontends can craft API messages that cause files to be written outside of the BuildKit state directory (bsc#1260967). - CVE-2026-33748: github.com/moby/buildkit: insufficient validation of Git URL fragment subdir components may allow access to files outside the checked-out Git repository (bsc#1261078). - CVE-2026-33997: Fixed privilege validation bypass during plugin (bsc#1265907). - CVE-2026-34040: Fixed Authz zero length regression (bsc#1265929).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1260967
- https://bugzilla.suse.com/1261078
- https://bugzilla.suse.com/1265907
- https://bugzilla.suse.com/1265929
- https://www.suse.com/security/cve/CVE-2026-33747
- https://www.suse.com/security/cve/CVE-2026-33748
- https://www.suse.com/security/cve/CVE-2026-33997
- https://www.suse.com/security/cve/CVE-2026-34040
- https://www.suse.com/support/update/announcement/2026/suse-su-20262578-1/