Critical Vulnerabilities in Fedora Docker-Buildx and Buildkit
ID: 4acb0e59-062d-596f-ab4f-8138269e98f7
STIX ID: report--4acb0e59-062d-596f-ab4f-8138269e98f7
Feed Name: ThreatCluster
Threat Score
Fedora released updates on June 18, 2026 addressing two critical vulnerabilities: CVE-2026-39828 (unauthorized command execution in docker-buildx) and CVE-2026-39829 (denial of service via crafted public keys in docker-buildkit). The flaws, published May 22, 2026, affect Fedora 43 and 44; administrators are advised to update immediately using dnf to mitigate integrity and availability risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
