NULL Pointer Dereference Affecting github.com/moby/buildkit/solver/llbsolver/ops package, versions <0.31.2


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.24% (16th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMMOBYBUILDKITSOLVERLLBSOLVEROPS-18265271
  • published23 Jul 2026
  • disclosed21 Jul 2026
  • creditUnknown

Introduced: 21 Jul 2026

CVE-2026-15792  (opens in a new tab)
CWE-476  (opens in a new tab)

How to fix?

Upgrade github.com/moby/buildkit/solver/llbsolver/ops to version 0.31.2 or higher.

Overview

Affected versions of this package are vulnerable to NULL Pointer Dereference through the LLB solver and llbsolver operation handling in solver/llbsolver/ops and solver/llbsolver/vertex.go. An attacker can crash the BuildKit daemon by supplying a malicious frontend or LLB definition with negative or out-of-range op input indices, or by omitting required diff inputs, causing a slice-index panic or nil pointer dereference during load and cache-key computation.

CVSS Base Scores

version 4.0
version 3.1