What changed in Docker Engine from 25 to 29
9 releases numbered after v25.0.17 up to and including v29.8.0, stable releases only. v25.0.17 and v29.8.0 are the newest stable releases of 25 and 29 we track; this page follows them as new ones ship.
- 6 CVEs mentioned
- 1 removes or deprecates something
- 5 releases carry a version number we could not place against this range and are not shown; the full changelog has them.
83 changes across 9 releases
- Add HostConfig.Umask option and a corresponding --umask <octal> flag to docker create/docker run to set the umask for a container's main process, execs, and healthchecks
- Add support for attaching service names, environments, and custom CloudWatch entity attributes to logs from the awslogs logging driver
- Remote network-driver plugins can now set the container-side interface name via the DstName field in their Join response
- Reserve network names "container" and "container:" to prevent creation of unusable networks
- Add annotation filter to container listings (docker ps, GET /containers/json) allowing to filter containers by their annotations
- Add an experimental embedded-containerd feature that runs containerd inside the daemon process instead of as a separate managed process
- Add the default-stop-timeout daemon option to configure the stop timeout assigned to containers without an explicit timeout
- Add shell completion for --filter names and known values to docker service ls, docker service ps, and docker node ps
- POST /containers/{id}/update endpoint now supports per-device blkio resource settings
- Add GET /images/{name}/attestations endpoint to retrieve in-toto attestation statements such as SLSA provenance and SPDX SBOM attached to an image, with support for optional platform selection, predicate type filtering, and statement query parameter
- The --password flag on docker login now accepts - to pass the password through STDIN as alternative to --password-stdin
- Reduce gossip traffic generated by a node that repeatedly disconnects and rejoins the cluster
- Spread the daemon's periodic Swarm overlay network gossip and synchronization work over time, avoiding recurring bursts of CPU and network usage
- Swarm service-mesh published ports now use the same infrastructure as published ports for local containers
- Update RootlessKit to v3.1.0, adding support for the pesto port driver in rootless mode
- Update minimum supported Go version to 1.26
- Update BuildKit to v0.32.2
- Improve compatibility with more nftables releases by terminating base-chain policies with a semicolon
- Mount type image is no longer experimental
- Improve the error returned when a container hostname exceeds Linux's 64-byte limit
- Update containerd (static binaries) to v2.2.6
- Update Go runtime to 1.26.5
- Update RootlessKit to v3.0.2
- Update containerd (static binaries) to v2.2.5
- Update BuildKit to v0.31.1
- Update runc in static binaries to v1.3.6
- Update BuildKit to v0.31.0
- Allow the nftables firewall mode to be used with a daemon linked against libnftables when the nft command is not installed on the system
- Mitigate a crash in libnftables when using nftables as the firewall backend by changing the default build option to execute the nft command instead of linking against libnftables
- Update containerd (static binaries only) to v2.2.4
- Update Go runtime to 1.26.4
- Update RootlessKit to v3.0.1
- Fix docker network inspect failing to find a healthy Swarm network when another Swarm network could not be allocated
- Fix a node gossiping a superseded value for a Swarm service discovery entry after concurrent updates to the same key
- Fix Swarm service names failing to resolve on a node indefinitely after it misses a network membership announcement
- Fix Swarm service names failing to resolve on healthy nodes after a transient node failure
- Prevent dockerd from hanging when the nft command produces enough stderr output to fill its pipe
- Fix --disable-host-loopback not being enforced for the pasta network driver in rootless mode
- Fix docker image inspect reporting a smaller image size than docker image ls with containerd image store
- Fix slower image pulls caused by repeated registry authentication within a single pull with containerd image store
- Fix docker service create and docker service update panicking when the same environment variable is passed more than once
- Fix a regression introduced in Docker Engine 29.7.0 that caused image pulls to reject images containing absolute hardlink targets
- Fix a regression introduced in Docker Engine 29.7.0 that could cause image pulls and docker cp to fail on older Linux kernels when applying file permissions
- Fix a regression that prevented pulling images whose layers contain directories without explicit parent directory entries
- Fix a regression where the CopyToContainer rejects container paths that traverse absolute symlinks, such as /var/run -> /run
- Fix a daemon panic when cleanup of a container's network interface fails while the container is being disconnected from a network
- Fix a daemon panic when removing swarm ingress ports after failing to bind an ingress proxy listener
- Keep the cgroup mount for containers with --net=host
- containerd image store: Fix daemon-wide concurrent download and upload limits for pulls and pushes not being honored
- Fix docker cp -a using the wrong file owner when copying files into containers with user namespace remapping enabled
- Fix docker cp from a Windows container silently returning a file instead of an error when the source path ends with a separator but is not a directory
- Fix docker stats reporting all zeros for running Windows containers when using the containerd runtime
- Fix docker stats reporting empty network stats for running Windows containers when using the containerd runtime
- Fix a typo in the docker create --pull flag description
- Fix Swarm service updates failing due to file exists errors when a VIP IP alias already exists on the LB endpoint interface
- Fix Swarm tasks being rejected when their image could not be pulled from the registry but was already present on the node
- Prevent live-restored volumes from retaining active mount references when containers exit during daemon startup
- Suppress the No such container error when docker rm --force succeeds for a nonexistent container
- docker image push now respects NO_COLOR
- Fix docker system prune with containerd image store to include unpacked image data when reporting reclaimed space
- Fix docker system df image size reporting to count only snapshots directly used by images
- Fix registry authentication failures during worker image pulls being reported as misleading 'No such image' error
- Fix default BuildKit GC policy to prune reproducible cache types as intended
- Fix explicit file modes being filtered by the daemon umask, including COPY --chmod permissions
- Fix image selection with the containerd image store on amd64 hosts when images provide amd64 variant-specific manifests
- Don't publish container ports on host ports listed in net.ipv4.ip_local_reserved_ports when dynamically allocating ports
- Fix a race condition in overlay network bulk sync that caused approximately 30 second DNS resolution delays on newly joined swarm nodes
- Silence the spurious warning 'IPv4 forwarding is disabled' in rootless mode
- Reduce docker system df errors when images are pruned at the same time with the containerd image store
- Fix AWS IMDS access with gvisor-tap-vsock and UDP port forwarding for non-loopback clients
- Fix installation of plugins that require host networking
- Fix docker cp failing with "mkdirat: file exists" when a container has a bind mount whose target traverses an in-container symlink
- The Engine now returns a deprecation warning when a container connected to the default bridge is created with links specified
- Add daemon support for configuring the default container AppArmor profile template
- Prevent containers from using the 32-bit socketcall(2) path to create AF_VSOCK sockets and communicate with host virtual machines by adding AppArmor and SELinux policy rules
- Update github.com/moby/go-archive to v0.3.0 to fix CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h
- Fix CVE-2026-15793: Git source checkout from a bundle file could lead to command injection
- Fix CVE-2026-15792: Incorrect parameters sent from a frontend could cause a panic
- Fix CVE-2026-15791: An LLB file operation could be tricked into removing the contents of the /tmp directory
- Fix CVE-2026-15789: A malicious client could bypass destination directory validation when uploading local sources
- Fix CVE-2026-15788: A WCOW cache mount source selector could resolve NTFS junctions outside of the cache root
- Fix a vulnerability where a malicious image could supply a malicious /etc/passwd or /etc/group-style file causing excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions
- Fix a vulnerability where a custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement
Original release notes, newest first
The list above is our reading of these notes; the originals from Docker are here, one fold per release.
v29.8.0v29.8.0
29.8.0
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
New
- Add
HostConfig.Umaskoption and a corresponding--umask <octal>flag todocker create/docker runto set the umask for a container's main process, execs, and healthchecks. moby/moby#53463, docker/cli#7108 - Add support for attaching service names, environments, and custom CloudWatch entity attributes to logs from the
awslogslogging driver. moby/moby#52632
Security
- Add daemon support for configuring the default container AppArmor profile template. moby/moby#52771
- Prevent containers from using the 32-bit
socketcall(2)path to createAF_VSOCKsockets and communicate with host virtual machines by adding AppArmor and SELinux policy rules. moby/moby#53551
Networking
- Fix
docker network inspectfailing to find a healthy Swarm network when another Swarm network could not be allocated. moby/moby#53325 - Fix a node gossiping a superseded value for a Swarm service discovery entry after concurrent updates to the same key. moby/moby#53479
- Fix Swarm service names failing to resolve on a node indefinitely after it misses a network membership announcement. moby/moby#53437
- Fix Swarm service names failing to resolve on healthy nodes after a transient node failure. moby/moby#53142
- Prevent dockerd from hanging when the nft command produces enough stderr output to fill its pipe. moby/moby#53517
- Reduce gossip traffic generated by a node that repeatedly disconnects and rejoins the cluster. moby/moby#53479
- Remote network-driver plugins can now set the container-side interface name via the
DstNamefield in theirJoinresponse. moby/moby#52866 - Reserve network names "container" and "container:" to prevent creation of unusable networks. moby/moby#51973
- Spread the daemon's periodic Swarm overlay network gossip and synchronization work over time, avoiding recurring bursts of CPU and network usage. moby/moby#53475
- Swarm service-mesh published ports now use the same infrastructure as published ports for local containers. moby/moby#53118
Rootless
- Fix
--disable-host-loopbacknot being enforced for thepastanetwork driver in rootless mode. moby/moby#53358 - Update RootlessKit to v3.1.0, adding support for the
pestoport driver in rootless mode. SetDOCKERD_ROOTLESS_ROOTLESSKIT_PORT_DRIVER=pestoto use it; it requires thepastanetwork driver and supports IPv4 only. moby/moby#53358
Go SDK
- Update minimum supported Go version to 1.26. docker/cli#7258
Bug fixes and enhancements
- Add
annotationfilter to container listings (docker ps,GET /containers/json) allowing to filter containers by their annotations. moby/moby#53538 - containerd image store: Fix
docker image inspectreporting a smaller image size thandocker image ls. moby/moby#53426 - containerd image store: Fix slower image pulls caused by repeated registry authentication within a single pull. moby/moby#53497
- Do not log expected image signature identity misses as errors for containerd image store images. moby/moby#53495
- dockerd now uses the embedded containerd if no system containerd service is configured and containerd is not installed. moby/moby#53388
- Fix
GET /images/{name}/jsonnot including unpacked snapshot usage inSizewhen using the containerd image store. moby/moby#53426 - Fix classic-builder cache for Dockerfile stages that select a non-host platform with
FROM --platform. moby/moby#53503 - Fix CLI panic when
DOCKER_HOSTor-Hspecifies an invalid host. docker/cli#7280 - Fix health checks being delayed for too long when the start interval is longer than the start period. moby/moby#52317
- Fix inconsistent mount ordering in
docker inspectoutput (GET /containers/{id}/json) and container listings (docker ps,GET /containers/json). moby/moby#53534 - Fix NRI container metadata so
Container.Argsincludes the resolved executable asargv[0], matching the process launched in the container instead of only the DockerCmd. moby/moby#53423 - Fix Swarm service creation failing when an automatically generated name is already in use. moby/moby#53468
- Fix the container root directory
/being world-writable when using thebtrfsstorage driver. moby/moby#53500 - Fixed
docker pssorting published ports lexicographically instead of numerically. docker/cli#7144 - Preserve service mount order during forced updates to avoid an unnecessary rollout on the next stack deploy. docker/cli#7227
- Prevent containerd's v2 CRI plugins from loading when CRI is disabled. moby/moby#53564
- Print plugin hook output (e.g. the "What's next:" hint) after the command's error message instead of before it. docker/cli#6976
- Reject checkpoint IDs containing path separators to prevent access outside the container checkpoint directory. moby/moby#53377
Packaging updates
- Update BuildKit to v0.33.0. moby/moby#53554
- Update containerd (static binaries) to v2.3.4. moby/moby#53409
- Update Go runtime to 1.26.8. moby/moby#53550, docker/cli#7274
- Update runc (in static binaries) to v1.5.1. moby/moby#52306
v29.7.2v29.7.2
29.7.2
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug fixes and enhancements
- Fix
docker service createanddocker service updatepanicking when the same environment variable is passed more than once. docker/cli#7145 - Fix a regression introduced in Docker Engine 29.7.0 that caused image pulls to reject images containing absolute hardlink targets, as produced by some image builders. moby/moby#53305
- Fix a regression introduced in Docker Engine 29.7.0 that could cause image pulls and
docker cpto fail on older Linux kernels when applying file permissions, including for device nodes. moby/moby#53305
Packaging updates
- Update BuildKit to v0.32.2. moby/moby#53300
Networking
- Improve compatibility with more nftables releases by terminating base-chain policies with a semicolon. moby/moby#53303
v29.7.1v29.7.1
29.7.1
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug fixes and enhancements
- Fix a regression that prevented pulling images whose layers contain directories without explicit parent directory entries. moby/moby#53260
- Fix a regression where the
CopyToContainerrejects container paths that traverse absolute symlinks, such as/var/run->/run. moby/moby#53261
v29.7.0v29.7.0
29.7.0
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
New
- Add an experimental
embedded-containerdfeature that runs containerd inside the daemon process instead of as a separate managed process. moby/moby#52898 - Mount type
imageis no longer experimental. moby/moby#52998 - Add the
default-stop-timeoutdaemon option to configure the stop timeout assigned to containers without an explicit timeout. moby/moby#53146
Security
This release includes a fix for a security vulnerability affecting Docker Engine and related components.
- Update github.com/moby/go-archive to v0.3.0 to fix CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h. moby/moby#53247, docker/cli#7139
Networking
- Fix a daemon panic when cleanup of a container's network interface fails while the container is being disconnected from a network. moby/moby#53237
- Fix a daemon panic when removing swarm ingress ports after failing to bind an ingress proxy listener. moby/moby#53022
Rootless
- Keep the cgroup mount for containers with
--net=host. moby/moby#52318
Bug fixes and enhancements
- Add shell completion for
--filternames and known values todocker service ls,docker service ps, anddocker node ps. docker/cli#7124 - containerd image store: Fix daemon-wide concurrent download and upload limits for pulls and pushes not being honored. moby/moby#53081
- To preserve the previous unlimited startup behavior, configure "max-concurrent-downloads" and "max-concurrent-uploads" to 0
- Fix
docker cp -ausing the wrong file owner when copying files into containers with user namespace remapping enabled. moby/moby#53084 - Fix
docker cpfrom a Windows container silently returning a file instead of an error when the source path ends with a separator but is not a directory. moby/moby#53123 - Fix
docker statsreporting all zeros for running Windows containers when using the containerd runtime. moby/moby#53101 - Fix
docker statsreporting empty network stats for running Windows containers when using the containerd runtime. moby/moby#53219 - Fix a typo in the
docker create --pullflag description. docker/cli#7103 - Fix Swarm service updates failing due to "file exists" errors when a VIP IP alias already exists on the LB endpoint interface. moby/moby#51657
- Fix Swarm tasks being rejected when their image could not be pulled from the registry but was already present on the node. moby/moby#53212
- Improve the error returned when a container hostname exceeds Linux's 64-byte limit. moby/moby#53121
- Prevent live-restored volumes from retaining active mount references when containers exit during daemon startup. moby/moby#53115
- Suppress the “No such container” error when
docker rm --forcesucceeds for a nonexistent container. docker/cli#7110
Packaging updates
- Update Go runtime to 1.26.5. docker/cli#7087
- Update BuildKit to v0.32.0. moby/moby#53234
- Update containerd (static binaries) to v2.3.3. moby/moby#53050
- Update runc (in static binaries) to v1.4.3. moby/moby#50960
v29.6.2v29.6.2
29.6.2
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Security
This release includes fixes for multiple security vulnerabilities affecting Docker Engine.
- CVE-2026-15793: Git source checkout from a bundle file could lead to command injection. GHSA-hw3h-2gp9-cxpv
- CVE-2026-15792: Incorrect parameters sent from a frontend could cause a panic. GHSA-qx3x-mv6r-52p6
- CVE-2026-15791: An LLB file operation could be tricked into removing the contents of the
/tmpdirectory. GHSA-32pv-7hq5-qhwq - CVE-2026-15789: A malicious client could bypass destination directory validation when uploading local sources. GHSA-g2h8-426c-7976
- CVE-2026-15788: A WCOW cache mount source selector could resolve NTFS junctions outside of the cache root. GHSA-388v-wmr2-g2v2
Packaging updates
- Update containerd (static binaries) to v2.2.6. moby/moby#53051
- Update Go runtime to 1.26.5. moby/moby#53027
Rootless
- Update RootlessKit to v3.0.2. moby/moby#53054
v29.6.1v29.6.1
29.6.1
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Security
This release includes fixes for multiple security vulnerabilities affecting Docker Engine.
- A malicious image could supply a malicious
/etc/passwdor/etc/group-style file causing excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions. GHSA-mjcv-p78q-w5fw, GHSA-jpcc-p29g-p8mq, GHSA-72x6-4j93-7w86 - A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers. GHSA-7236-3392-c5c6
Bug fixes and enhancements
- Update containerd (static binaries) to v2.2.5. moby/moby#52950
Packaging updates
- Update BuildKit to v0.31.1. moby/moby#52954
v29.6.0v29.6.0
29.6.0
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
New
POST /containers/{id}/updatenow supports per-device blkio resource settings. moby/moby#52651- Add
GET /images/{name}/attestationsendpoint to retrieve in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image. Supports optional platform selection, predicate type filtering, and a statement query parameter for verbatim statement bodies.
Bug fixes and enhancements
docker image pushnow respectsNO_COLOR. docker/cli#6957- containerd image store: Fix
docker system pruneto include unpacked image data when reporting reclaimed space. moby/moby#52905 - Fix
docker system dfimage size reporting to count only snapshots directly used by images. moby/moby#52901 - Fix a bug where registry authentication failures during worker image pulls were reported as a misleading “No such image” error. moby/moby#52698
- Fix default BuildKit GC policy to prune reproducible cache types as intended. moby/moby#52814
- Fix explicit file modes being filtered by the daemon umask, including
COPY --chmodpermissions. moby/moby#52892 - Fix image selection with the containerd image store on amd64 hosts when images provide amd64 variant-specific manifests. moby/moby#52773
- The
--passwordflag ondocker loginnow accepts-to pass the password through STDIN as alternative to--password-stdin. docker/cli#7029
Packaging updates
- Update runc (in static binaries) to v1.3.6. moby/moby#52883
- Update BuildKit to v0.31.0. moby/moby#52904
Networking
- Allow the nftables firewall mode to be used with a daemon that is linked against libnftables when the
nftcommand is not installed on the system. moby/moby#52820 - Don't publish container ports on host ports listed in
net.ipv4.ip_local_reserved_portswhen dynamically allocating ports. moby/moby#52818 - Fix a race condition in overlay network bulk sync that caused ~30s DNS resolution delays on newly joined swarm nodes. moby/moby#52862
- Mitigate a crash in libnftables when using nftables as the firewall backend by changing the default build option to execute the
nftcommand instead. Users building dockerd from source can opt into linking against libnftables by building with thelibnftablesbuild tag. moby/moby#52886
Rootless
- Silence the spurious warning "IPv4 forwarding is disabled". moby/moby#52742
Deprecations
- The Engine now returns a deprecation warning when a container connected to the default bridge is created with links specified. moby/moby#47427
v29.5.3v29.5.3
29.5.3
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug fixes and enhancements
- Reduce
docker system dferrors when images are pruned at the same time with the containerd image store. moby/moby#52672
Packaging updates
- Update containerd (static binaries only) to v2.2.4. moby/moby#52683
- Update Go runtime to 1.26.4. moby/moby#52753, docker/cli#7025
- Update RootlessKit to v3.0.1. moby/moby#52710
Rootless
- Fix AWS IMDS access with
gvisor-tap-vsockand UDP port forwarding for non-loopback clients. moby/moby#52710 - Fix installation of plugins that require host networking. moby/moby#52735
v29.5.2v29.5.2
29.5.2
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug fixes and enhancements
- Fix
docker cpfailing with "mkdirat: file exists" when a container has a bind mount whose target traverses an in-container symlink (e.g./var/run -> /run). moby/moby#52655