Skip to content

Releases: moby/moby

v29.9.0

Choose a tag to compare

@vvoland vvoland released this 08 Oct 21:34
docker-v29.9.0
a5b58c9

29.9.0

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Security

The Go runtime update fixes the following security vulnerabilities in Docker Engine:

  • CVE-2026-97032: An HTTP/2 client could crash the daemon by changing the HPACK header table size while sending requests. golang/go#81867
  • CVE-2026-78659: An HTTP/2 client could exhaust daemon memory by declaring a large number of fields in a Trailer header, bypassing the header size limits. golang/go#81857
  • CVE-2026-78663: An HTTP/2 client could bypass the connection-level flow control limit by resetting streams, making the daemon buffer more request data than the limit allows. golang/go#81743
  • CVE-2026-78669: An HTTP/2 client could cause excessive daemon CPU use by opening many streams and repeatedly changing the initial window size. golang/go#81742
  • CVE-2026-56857: On Windows, the daemon could create a directory outside its data root if someone with write access to the data root had placed a junction there. golang/go#81739

The golang.org/x/net update to v0.60.0 applies the same HTTP/2 fixes to the deprecated /grpc endpoint and to the gRPC server that BuildKit runs for frontend containers, such as images referenced by a # syntax= directive.

Bug fixes and enhancements

  • containerd image store: Add the lazy-pull daemon feature to control whether docker pull skips downloading layer content that the snapshotter already provides. Lazy pulls are enabled by default for known remote snapshotters (nydus, overlaybd, soci, stargz). moby/moby#53877
  • containerd image store: Fix pulls skipping required layer blobs when unpacked layers already exist, leaving images runnable but incomplete for export or push. moby/moby#53615
  • Fix docker container create --name reporting a misleading validation error mentioning invalid characters instead of invalid name length. moby/moby#53484
  • Fix a connection leak to the RootlessKit API socket on every GET /version request in rootless mode. moby/moby#53836
  • Improve Windows service registration and unregistration cleanup, including making service unregistration (--unregister-service) idempotent. moby/moby#53845

Packaging updates

Networking

  • Allow IPv6 Neighbour Discovery between containers on a bridge network with inter-container communication disabled, matching the existing IPv4 behaviour. moby/moby#53723
  • Fix docker ps and GET /containers/json omitting published ports for networks using routed gateway mode. moby/moby#53693
  • Fix a bug where a restarted daemon could be dropped from a peer's service discovery and load balancing until it rejoined the gossip cluster. moby/moby#53688
  • Fix a published port being unreachable from another container on the same network when inter-container communication is disabled, including Swarm services published through the routing mesh. moby/moby#53723
  • Fix an issue where errors programming the kernel to encrypt the overlay network data-plane could in some circumstances lead to encrypted-overlay-network traffic to some nodes being transmitted in cleartext. As the receiving peer would drop cleartext packets for encrypted overlay networks as spoofed, the loss of confidentiality is limited to unidirectional flows (e.g. UDP DNS queries) and handshake attempts that never proceed (e.g. TCP SYN). moby/moby#53420
  • Fix connecting live-restored containers with an implicit host-gateway mapping to additional networks. moby/moby#53093
  • Fix overlay peers becoming unreachable after a node rejoins the cluster or a service is redeployed, when the VXLAN device had already learned a dynamic FDB entry for the peer. moby/moby#53663
  • Fix Swarm tasks on overlay networks being rejected when the daemon can't write to /var/lib/docker. moby/moby#53848
  • Published Swarm-service ports are accessible at the host's IPv6 addresses when the userland proxy is enabled. A change introduced in v29.8.0 incidentally enabled this functionality; it is a tested and supported feature as of v29.9.0. moby/moby#53727
  • Release a node's IPsec security associations and policies when the last container leaves an encrypted overlay network, instead of leaking them until the daemon restarts. moby/moby#53420
  • Restore the logic to remove the empty DOCKER-INGRESS iptables chain, and the FORWARD rule that jumps to it, left behind by Docker Engine 28.0.0 and earlier. moby/moby#53825

Rootless

client/v0.6.2

Choose a tag to compare

@vvoland vvoland released this 08 Oct 20:06
client/v0.6.2
21a2258

0.6.2

Changelog

  • client: bump github.com/docker/go-connections v0.8.2, github.com/Azure/go-ansiterm 8c912ac31dd4. moby/moby#53891
  • Fix request cancellation and deadlines during client HTTP upgrade handshakes. moby/moby#53889

v29.9.0-rc.2

v29.9.0-rc.2 Pre-release
Pre-release

Choose a tag to compare

@vvoland vvoland released this 07 Oct 20:11
docker-v29.9.0-rc.2
a2a604e

29.9.0-rc.2

For a full list of changes from the last release candidate refer to the diff:

Bug fixes and enhancements

  • containerd image store: Add the lazy-pull daemon feature to control whether docker pull skips downloading layer content that the snapshotter already provides. Lazy pulls are enabled by default for known remote snapshotters (nydus, overlaybd, soci, stargz). moby/moby#53877
  • containerd image store: Fix a regression in v29.9.0-rc.1 where docker pull downloaded all layer content when using a remote snapshotter such as stargz. moby/moby#53877
  • Improve Windows service registration and unregistration cleanup, including making service unregistration (--unregister-service) idempotent. moby/moby#53845

Packaging updates

Networking

  • Fix Swarm tasks on overlay networks being rejected when the daemon can't write to /var/lib/docker. moby/moby#53848

client/v0.6.1

Choose a tag to compare

@vvoland vvoland released this 01 Oct 18:24
client/v0.6.1
a2398db

0.6.1

Changelog

api/v1.56.1

Choose a tag to compare

@vvoland vvoland released this 01 Oct 17:59
api/v1.56.1
14ebc60

1.56.1

Changelog

v29.9.0-rc.1

v29.9.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@vvoland vvoland released this 01 Oct 20:56
docker-v29.9.0-rc.1
c8e2657

29.9.0-rc.1

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Bug fixes and enhancements

  • containerd image store: Fix pulls skipping required layer blobs when unpacked layers already exist, leaving images runnable but incomplete for export or push. moby/moby#53615
  • Fix docker container create --name reporting a misleading validation error mentioning invalid characters instead of invalid name length. moby/moby#53484
  • Fix a connection leak to the RootlessKit API socket on every GET /version request in rootless mode. moby/moby#53836

Packaging updates

Networking

  • Allow IPv6 Neighbour Discovery between containers on a bridge network with inter-container communication disabled, matching the existing IPv4 behaviour. moby/moby#53723
  • Fix docker ps and GET /containers/json omitting published ports for networks using routed gateway mode. moby/moby#53693
  • Fix a bug where a restarted daemon could be dropped from a peer's service discovery and load balancing until it rejoined the gossip cluster. moby/moby#53688
  • Fix a published port being unreachable from another container on the same network when inter-container communication is disabled, including Swarm services published through the routing mesh. moby/moby#53723
  • Fix an issue where errors programming the kernel to encrypt the overlay network data-plane could in some circumstances lead to encrypted-overlay-network traffic to some nodes being transmitted in cleartext. As the receiving peer would drop cleartext packets for encrypted overlay networks as spoofed, the loss of confidentiality is limited to unidirectional flows (e.g. UDP DNS queries) and handshake attempts that never proceed (e.g. TCP SYN). moby/moby#53420
  • Fix connecting live-restored containers with an implicit host-gateway mapping to additional networks. moby/moby#53093
  • Fix overlay peers becoming unreachable after a node rejoins the cluster or a service is redeployed, when the VXLAN device had already learned a dynamic FDB entry for the peer. moby/moby#53663
  • Published Swarm-service ports are accessible at the host's IPv6 addresses when the userland proxy is enabled. A change introduced in v29.8.0 incidentally enabled this functionality; it is a tested and supported feature as of v29.9.0. moby/moby#53727
  • Release a node's IPsec security associations and policies when the last container leaves an encrypted overlay network, instead of leaking them until the daemon restarts. moby/moby#53420
  • Restore the logic to remove the empty DOCKER-INGRESS iptables chain, and the FORWARD rule that jumps to it, left behind by Docker Engine 28.0.0 and earlier. moby/moby#53825

Rootless

v25.0.18

Choose a tag to compare

@corhere corhere released this 30 Sep 15:54
v25.0.18
eaa0057

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestone:

Bug fixes and enhancements

v29.8.2

Choose a tag to compare

@vvoland vvoland released this 30 Sep 20:28
docker-v29.8.2
8af9fe3

29.8.2

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Security

This release fixes the following security vulnerabilities in Docker Engine:

  • CVE-2026-53493: Pulling a crafted OCI image index with deeply nested or widely fanned-out descriptors could cause unbounded CPU and memory use. GHSA-pg57-6jwg-q645
  • CVE-2026-92543: A malicious DNS response could make registry connections skip TLS certificate verification or fall back to HTTP, exposing registry credentials or allowing image substitution. GHSA-7cfq-22r6-qp73
  • CVE-2026-92542: Unprivileged users on a Swarm node could inject forged Ethernet frames into encrypted overlay networks on peer nodes. GHSA-6m9p-4h64-m6vh

The BuildKit update fixes the following security vulnerabilities:

  • CVE-2026-93315: A build step could redirect proxy CA cleanup outside the build root filesystem, block it with a special file, or let the build succeed when cleanup failed. GHSA-2f5p-x9ph-g97x
  • CVE-2026-93316: A build that requested CDI devices could cause a daemon panic when CDI support was disabled, for example with "features": {"cdi": false} in daemon.json. GHSA-r456-g3gm-cvxf
  • CVE-2026-93317: With the containerd image store, a client using the low-level LLB API could poison the build cache with container blob contents that did not match their claimed digest. GHSA-p3rc-w3hc-pqvv
  • CVE-2026-93318: A malicious image could poison the build cache with layer DiffIDs that did not match the actual layer contents. GHSA-f2v9-hprr-32q3
  • CVE-2026-93319: A malicious external frontend could crash the daemon through gateway container lifecycle races or malformed requests and definitions. GHSA-4hgw-qrhw-fhg8
  • CVE-2026-93320: Daemon-side snapshot reads and LLB mkfile operations did not safely handle special files. GHSA-9728-qjrv-2xh2
  • CVE-2026-93321: A malformed LLB file operation with invalid symlink owner inputs could crash the daemon. GHSA-fjj4-h6vf-m9hj
  • CVE-2026-93322: A malformed LLB merge operation with mismatched input counts could crash the daemon. GHSA-cv6p-7w7g-xjwq
  • CVE-2026-93323: An oversized Dockerfile, .dockerignore, gateway file, or nested LLB definition could exhaust daemon memory. GHSA-mgqf-486f-49vp
  • CVE-2026-93326: A crafted Git build source could bypass source policy rules that match on the repository URL, through a Git bundle locator or a full remote URL that did not match the source identifier. GHSA-66hf-6vf5-87hc

Bug fixes and enhancements

  • Fix docker cp failing on a container with a bind-mounted socket nested inside another bind mount. moby/moby#53724
  • Fix docker info failing with an “invalid Prefix” error after reloading a daemon with custom default address pools. moby/moby#53812

Packaging updates

v29.8.1

Choose a tag to compare

@vvoland vvoland released this 15 Sep 17:05
docker-v29.8.1
464cd50

29.8.1

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Bug fixes and enhancements

  • containerd image store: Fix docker load leaving dangling images after loading an image that already exists. moby/moby#53595
  • Fix managed containerd logging a CRI pod-sandbox plugin dependency warning during startup. moby/moby#53585
  • Fix user-namespace detection on OpenVZ, where namespace inode numbers are virtualized. moby/moby#53605
  • Windows: Preserve hard links when committing a container, so a file with multiple names is stored once in the resulting image layer instead of once per name. moby/moby#53624

Packaging updates

Networking

  • Fix GET /networks returning a 500 status if an invalid 'type' filter was provided. moby/moby#53678

v29.8.0

Choose a tag to compare

@vvoland vvoland released this 03 Sep 22:31
docker-v29.8.0
3ce5872

29.8.0

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

New

  • Add HostConfig.Umask option and a corresponding --umask <octal> flag to docker create/docker run to set the umask for a container's main process, execs, and healthchecks. moby/moby#53463, docker/cli#7108
  • Add support for attaching service names, environments, and custom CloudWatch entity attributes to logs from the awslogs logging driver. moby/moby#52632

Security

Networking

  • Fix docker network inspect failing to find a healthy Swarm network when another Swarm network could not be allocated. moby/moby#53325
  • Fix a node gossiping a superseded value for a Swarm service discovery entry after concurrent updates to the same key. moby/moby#53479
  • Fix Swarm service names failing to resolve on a node indefinitely after it misses a network membership announcement. moby/moby#53437
  • Fix Swarm service names failing to resolve on healthy nodes after a transient node failure. moby/moby#53142
  • Prevent dockerd from hanging when the nft command produces enough stderr output to fill its pipe. moby/moby#53517
  • Reduce gossip traffic generated by a node that repeatedly disconnects and rejoins the cluster. moby/moby#53479
  • Remote network-driver plugins can now set the container-side interface name via the DstName field in their Join response. moby/moby#52866
  • Reserve network names "container" and "container:" to prevent creation of unusable networks. moby/moby#51973
  • Spread the daemon's periodic Swarm overlay network gossip and synchronization work over time, avoiding recurring bursts of CPU and network usage. moby/moby#53475
  • Swarm service-mesh published ports now use the same infrastructure as published ports for local containers. moby/moby#53118

Rootless

  • Fix --disable-host-loopback not being enforced for the pasta network driver in rootless mode. moby/moby#53358
  • Update RootlessKit to v3.1.0, adding support for the pesto port driver in rootless mode. Set DOCKERD_ROOTLESS_ROOTLESSKIT_PORT_DRIVER=pesto to use it; it requires the pasta network driver and supports IPv4 only. moby/moby#53358

Go SDK

Bug fixes and enhancements

  • Add annotation filter to container listings (docker ps, GET /containers/json) allowing to filter containers by their annotations. moby/moby#53538
  • containerd image store: Fix docker image inspect reporting a smaller image size than docker image ls. moby/moby#53426
  • containerd image store: Fix slower image pulls caused by repeated registry authentication within a single pull. moby/moby#53497
  • Do not log expected image signature identity misses as errors for containerd image store images. moby/moby#53495
  • dockerd now uses the embedded containerd if no system containerd service is configured and containerd is not installed. moby/moby#53388
  • Fix GET /images/{name}/json not including unpacked snapshot usage in Size when using the containerd image store. moby/moby#53426
  • Fix classic-builder cache for Dockerfile stages that select a non-host platform with FROM --platform. moby/moby#53503
  • Fix CLI panic when DOCKER_HOST or -H specifies an invalid host. docker/cli#7280
  • Fix health checks being delayed for too long when the start interval is longer than the start period. moby/moby#52317
  • Fix inconsistent mount ordering in docker inspect output (GET /containers/{id}/json) and container listings (docker ps, GET /containers/json). moby/moby#53534
  • Fix NRI container metadata so Container.Args includes the resolved executable as argv[0], matching the process launched in the container instead of only the Docker Cmd. moby/moby#53423
  • Fix Swarm service creation failing when an automatically generated name is already in use. moby/moby#53468
  • Fix the container root directory / being world-writable when using the btrfs storage driver. moby/moby#53500
  • Fixed docker ps sorting published ports lexicographically instead of numerically. docker/cli#7144
  • Preserve service mount order during forced updates to avoid an unnecessary rollout on the next stack deploy. docker/cli#7227
  • Prevent containerd's v2 CRI plugins from loading when CRI is disabled. moby/moby#53564
  • Print plugin hook output (e.g. the "What's next:" hint) after the command's error message instead of before it. docker/cli#6976
  • Reject checkpoint IDs containing path separators to prevent access outside the container checkpoint directory. moby/moby#53377

Packaging updates