Releases Index

Engine Release Notes

$npx @buildinternet/releases get docker-engine-release-notes
Mon
Wed
Fri
OctNovDecJanFebMarAprMayJunJulAugSepOct
Less
More
Releases6Avg2/moVersionsv29.7.0 to v29.8.2
v29.8.2

Docker Engine 29.8.2 fixes 13 security vulnerabilities: a malicious DNS response could make registry connections skip TLS certificate verification or fall back to HTTP, unprivileged users on a Swarm node could inject forged Ethernet frames into encrypted overlay networks, and pulling a crafted OCI image index could cause unbounded CPU and memory use. The BuildKit update addresses build cache poisoning via mismatched layer DiffIDs, daemon crashes from malformed LLB operations, and a source policy bypass in crafted Git build sources, plus fixes for docker cp on nested bind-mounted sockets and docker info failing after daemon reload with custom default address pools.

Read more →
v29.8.1

containerd image store no longer leaves dangling images when docker load loads an image that already exists, and GET /networks returns a proper error instead of a 500 for an invalid type filter. Windows commits now preserve hard links, user-namespace detection works on OpenVZ, and static containerd binaries are updated to v2.3.5.

Read more →
v29.8.0

New HostConfig.Umask option and docker run/create --umask flag set the umask for a container's main process, execs, and healthchecks. AppArmor and SELinux rules now block containers from using the 32-bit socketcall(2) path to create AF_VSOCK sockets and reach host virtual machines, plus a long tail of Swarm networking and containerd image store fixes.

Read more →
v29.7.2

Fixes regressions introduced in Engine 29.7.0 that caused image pulls to reject images with absolute hardlink targets and caused pulls and docker cp to fail on older Linux kernels when applying file permissions. Also fixes a panic in docker service create and docker service update when the same environment variable is passed twice, and updates BuildKit to v0.32.2.

Read more →
v29.7.1

Fixes a regression that prevented pulling images whose layers contain directories without explicit parent directory entries, and a regression where CopyToContainer rejected container paths traversing absolute symlinks such as /var/run to /run.

Read more →
v29.7.0

Updates github.com/moby/go-archive to v0.3.0 to fix CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h. Also adds an experimental embedded-containerd feature that runs containerd inside the daemon process, graduates the image mount type out of experimental, adds a default-stop-timeout daemon option, and fixes daemon panics during network disconnect cleanup and swarm ingress port removal.

Read more →
v29.4.3

CVE-2026-31431, which exposed AF_ALG sockets to 32-bit programs, is patched by replacing the socketcall(2) seccomp deny with targeted AppArmor (deny network alg) and SELinux (alg_socket) rules at the LSM layer. On SELinux systems, this requires selinux-enabled: true in daemon.json or via the --selinux-enabled flag. Also fixed the default AppArmor profile not being updated on daemon restart, which previously required a system reboot to pick up profile changes from upgrades.

Read more →

Security fixes:

  • CVE-2026-34040: Fix an authorization bypass in AuthZ plugins GHSA-x744-4wpc-v9h2
  • CVE-2026-33997: Fix a flaw in docker plugin install where privilege validation could be partially…
Read more →

New features:

  • Add bind-create-src option to --mount flag for bind mounts
  • CLI plugin hooks now fire on command failure and plugins can use "error-hooks" to show hints only when commands fail
  • Lower minimum API version from v1.44 to v1.40 (Docker 19.03)
Read more →

Bug fixes:

  • Update BuildKit to v0.27.1
  • Fix docker system df failing when run concurrently with docker system prune
  • Fix daemon handling of duplicate container exit events
  • Fix panic after failed daemon initialization
  • Fix encrypted overlay networks not passing…
Read more →

New features:

  • docker info now includes NRI section
  • Add experimental NRI support
  • New Identity field in inspect endpoint showing trusted origin information about images
Read more →
Last Checked
3mo ago
Tracking since Dec 12, 2025