Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
41 changes: 41 additions & 0 deletions content/manuals/engine/release-notes/29.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,47 @@ For more information about:
- Deprecated and removed features, see [Deprecated Engine Features](../deprecated.md).
- Changes to the Engine API, see [Engine API version history](/reference/api/engine/version-history/).

## 29.8.2

{{< release-date date="2026-09-30" >}}

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

- [docker/cli, 29.8.2 milestone](https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A29.8.2)
- [moby/moby, 29.8.2 milestone](https://github.com/moby/moby/issues?q=is%3Aclosed+milestone%3A29.8.2)

### Security

This release fixes the following security vulnerabilities in Docker Engine:

- **CVE-2026-53493**: Pulling a crafted OCI image index with deeply nested or widely fanned-out descriptors could cause unbounded CPU and memory use. [GHSA-pg57-6jwg-q645](https://github.com/containerd/containerd/security/advisories/GHSA-pg57-6jwg-q645)
- **CVE-2026-92543**: A malicious DNS response could make registry connections skip TLS certificate verification or fall back to HTTP, exposing registry credentials or allowing image substitution. [GHSA-7cfq-22r6-qp73](https://github.com/moby/moby/security/advisories/GHSA-7cfq-22r6-qp73)
- **CVE-2026-92542**: Unprivileged users on a Swarm node could inject forged Ethernet frames into encrypted overlay networks on peer nodes. [GHSA-6m9p-4h64-m6vh](https://github.com/moby/moby/security/advisories/GHSA-6m9p-4h64-m6vh)

The BuildKit update fixes the following security vulnerabilities:

- **CVE-2026-93315**: A build step could redirect proxy CA cleanup outside the build root filesystem, block it with a special file, or let the build succeed when cleanup failed. [GHSA-2f5p-x9ph-g97x](https://github.com/moby/buildkit/security/advisories/GHSA-2f5p-x9ph-g97x)
- **CVE-2026-93316**: A build that requested CDI devices could cause a daemon panic when CDI support was disabled, for example with `"features": {"cdi": false}` in `daemon.json`. [GHSA-r456-g3gm-cvxf](https://github.com/moby/buildkit/security/advisories/GHSA-r456-g3gm-cvxf)
- **CVE-2026-93317**: With the containerd image store, a client using the low-level LLB API could poison the build cache with container blob contents that did not match their claimed digest. [GHSA-p3rc-w3hc-pqvv](https://github.com/moby/buildkit/security/advisories/GHSA-p3rc-w3hc-pqvv)
- **CVE-2026-93318**: A malicious image could poison the build cache with layer DiffIDs that did not match the actual layer contents. [GHSA-f2v9-hprr-32q3](https://github.com/moby/buildkit/security/advisories/GHSA-f2v9-hprr-32q3)
- **CVE-2026-93319**: A malicious external frontend could crash the daemon through gateway container lifecycle races or malformed requests and definitions. [GHSA-4hgw-qrhw-fhg8](https://github.com/moby/buildkit/security/advisories/GHSA-4hgw-qrhw-fhg8)
- **CVE-2026-93320**: Daemon-side snapshot reads and LLB `mkfile` operations did not safely handle special files. [GHSA-9728-qjrv-2xh2](https://github.com/moby/buildkit/security/advisories/GHSA-9728-qjrv-2xh2)
- **CVE-2026-93321**: A malformed LLB file operation with invalid symlink owner inputs could crash the daemon. [GHSA-fjj4-h6vf-m9hj](https://github.com/moby/buildkit/security/advisories/GHSA-fjj4-h6vf-m9hj)
- **CVE-2026-93322**: A malformed LLB merge operation with mismatched input counts could crash the daemon. [GHSA-cv6p-7w7g-xjwq](https://github.com/moby/buildkit/security/advisories/GHSA-cv6p-7w7g-xjwq)
- **CVE-2026-93323**: An oversized Dockerfile, `.dockerignore`, gateway file, or nested LLB definition could exhaust daemon memory. [GHSA-mgqf-486f-49vp](https://github.com/moby/buildkit/security/advisories/GHSA-mgqf-486f-49vp)
- **CVE-2026-93326**: A crafted Git build source could bypass source policy rules that match on the repository URL, through a Git bundle locator or a full remote URL that did not match the source identifier. [GHSA-66hf-6vf5-87hc](https://github.com/moby/buildkit/security/advisories/GHSA-66hf-6vf5-87hc)

### Bug fixes and enhancements

- Fix `docker cp` failing on a container with a bind-mounted socket nested inside another bind mount. [moby/moby#53724](https://github.com/moby/moby/pull/53724)
- Fix `docker info` failing with an “invalid Prefix” error after reloading a daemon with custom default address pools. [moby/moby#53812](https://github.com/moby/moby/pull/53812)

### Packaging updates

- Update BuildKit to [v0.33.1](https://github.com/moby/buildkit/releases/tag/v0.33.1). [moby/moby#53823](https://github.com/moby/moby/pull/53823)
- Update containerd (static binaries) to [v2.3.6](https://github.com/containerd/containerd/releases/tag/v2.3.6). [moby/moby#53778](https://github.com/moby/moby/pull/53778)
- Update runc (in static binaries) to [v1.5.2](https://github.com/opencontainers/runc/releases/tag/v1.5.2). [moby/moby#53811](https://github.com/moby/moby/pull/53811)

## 29.8.1

{{< release-date date="2026-09-15" >}}
Expand Down
4 changes: 2 additions & 2 deletions hugo.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -175,10 +175,10 @@ params:
# Latest version of the Docker Engine API
latest_engine_api_version: "1.56"
# Latest version of Docker Engine
docker_ce_version: "29.8.1"
docker_ce_version: "29.8.2"
Comment thread
vvoland marked this conversation as resolved.
# Previous version of the Docker Engine
# (Used to show e.g., "latest" and "latest"-1 in engine install examples
docker_ce_version_prev: "29.8.0"
docker_ce_version_prev: "29.8.1"
# Latest Docker Compose version
compose_version: "v5.5.0"
# Latest BuildKit version
Expand Down
Loading