Allowlist mesa CVE-2026-40393 in PT 2.9 EC2 training images#6273
Merged
bhanutejagk merged 4 commits intoJun 19, 2026
Merged
Conversation
CVE-2026-40393 is an out-of-bounds memory access in Mesa's WebGPU code path (alloca size derived from untrusted input). Fixed upstream in mesa 25.3.6 / 26.0.1; Ubuntu 22.04 (jammy) is currently "Needs evaluation" with no patched package available yet. DLC training containers do not expose a WebGPU or browser rendering surface to untrusted content. mesa is pulled in transitively via the libgl1-mesa-glx system package and is not invoked by training workloads, so the vulnerable code path is unreachable in these images. Adds the entry to: - pytorch/training/docker/2.9/py3/Dockerfile.ec2.cpu.os_scan_allowlist.json - pytorch/training/docker/2.9/py3/cu130/Dockerfile.ec2.gpu.os_scan_allowlist.json Existing allowlist entries (black, torch, flash_attn) are preserved.
added 3 commits
June 19, 2026 00:35
Limit dlc_developer_config.toml to building PyTorch training images for the mesa CVE-2026-40393 allowlist on PT 2.9 EC2 training Dockerfiles. SageMaker local/remote test paths are disabled since they don't validate this allowlist; EC2, ECS, EKS, sanity, and security tests remain enabled.
Targets the PT 2.9 EC2 training buildspec for CI on the mesa CVE-2026-40393 allowlist branch so only the images covered by the allowlist are rebuilt and tested.
Restores dlc_developer_config.toml to upstream master so the buildspec override merge-gate passes. The PT 2.9 EC2 mesa CVE-2026-40393 allowlist remains in this branch.
sallyseok
approved these changes
Jun 19, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
CVE-2026-40393 is an out-of-bounds memory access in Mesa's WebGPU code path (alloca size derived from untrusted input). Fixed upstream in mesa 25.3.6 / 26.0.1; Ubuntu 22.04 (jammy) is currently "Needs evaluation" with no patched package available yet.
DLC training containers do not expose a WebGPU or browser rendering surface to untrusted content. mesa is pulled in transitively via the libgl1-mesa-glx system package and is not invoked by training workloads, so the vulnerable code path is unreachable in these images.
Adds the entry to:
Existing allowlist entries (black, torch, flash_attn) are preserved.
Purpose
Test Plan
Test Result
ebc9a97 - passed all tests
Toggle if you are merging into master Branch
By default, docker image builds and tests are disabled. Two ways to run builds and tests:
How to use the helper utility for updating dlc_developer_config.toml
Assuming your remote is called
origin(you can find out more withgit remote -v)...python src/prepare_dlc_dev_environment.py -b </path/to/buildspec.yml> -cp originpython src/prepare_dlc_dev_environment.py -b </path/to/buildspec.yml> -t sanity_tests -cp originpython src/prepare_dlc_dev_environment.py -rcp originNOTE: If you are creating a PR for a new framework version, please ensure success of the local, standard, rc, and efa sagemaker tests by updating the dlc_developer_config.toml file:
sagemaker_remote_tests = truesagemaker_efa_tests = truesagemaker_rc_tests = truesagemaker_local_tests = trueHow to use PR description
Use the code block below to uncomment commands and run the PR CodeBuild jobs. There are two commands available:# /buildspec <buildspec_path># /buildspec pytorch/training/buildspec.yml# /tests <test_list># /tests sanity security ec2sanity, security, ec2, ecs, eks, sagemaker, sagemaker-local.Toggle if you are merging into main Branch
PR Checklist
pre-commit run --all-fileslocally before creating this PR. (Read DEVELOPMENT.md for details).