What changed in Docker Engine from 25 to 29

9 releases numbered after v25.0.17 up to and including v29.8.0, stable releases only. v25.0.17 and v29.8.0 are the newest stable releases of 25 and 29 we track; this page follows them as new ones ship.

83 changes across 9 releases

Added 11

v29.8.0

  • Add HostConfig.Umask option and a corresponding --umask <octal> flag to docker create/docker run to set the umask for a container's main process, execs, and healthchecks
  • Add support for attaching service names, environments, and custom CloudWatch entity attributes to logs from the awslogs logging driver
  • Remote network-driver plugins can now set the container-side interface name via the DstName field in their Join response
  • Reserve network names "container" and "container:" to prevent creation of unusable networks
  • Add annotation filter to container listings (docker ps, GET /containers/json) allowing to filter containers by their annotations

v29.7.0

  • Add an experimental embedded-containerd feature that runs containerd inside the daemon process instead of as a separate managed process
  • Add the default-stop-timeout daemon option to configure the stop timeout assigned to containers without an explicit timeout
  • Add shell completion for --filter names and known values to docker service ls, docker service ps, and docker node ps

v29.6.0

  • POST /containers/{id}/update endpoint now supports per-device blkio resource settings
  • Add GET /images/{name}/attestations endpoint to retrieve in-toto attestation statements such as SLSA provenance and SPDX SBOM attached to an image, with support for optional platform selection, predicate type filtering, and statement query parameter
  • The --password flag on docker login now accepts - to pass the password through STDIN as alternative to --password-stdin
Changed 21

v29.8.0

  • Reduce gossip traffic generated by a node that repeatedly disconnects and rejoins the cluster
  • Spread the daemon's periodic Swarm overlay network gossip and synchronization work over time, avoiding recurring bursts of CPU and network usage
  • Swarm service-mesh published ports now use the same infrastructure as published ports for local containers
  • Update RootlessKit to v3.1.0, adding support for the pesto port driver in rootless mode
  • Update minimum supported Go version to 1.26

v29.7.2

  • Update BuildKit to v0.32.2
  • Improve compatibility with more nftables releases by terminating base-chain policies with a semicolon

v29.7.0

  • Mount type image is no longer experimental
  • Improve the error returned when a container hostname exceeds Linux's 64-byte limit

v29.6.2

  • Update containerd (static binaries) to v2.2.6
  • Update Go runtime to 1.26.5
  • Update RootlessKit to v3.0.2

v29.6.1

  • Update containerd (static binaries) to v2.2.5
  • Update BuildKit to v0.31.1

v29.6.0

  • Update runc in static binaries to v1.3.6
  • Update BuildKit to v0.31.0
  • Allow the nftables firewall mode to be used with a daemon linked against libnftables when the nft command is not installed on the system
  • Mitigate a crash in libnftables when using nftables as the firewall backend by changing the default build option to execute the nft command instead of linking against libnftables

v29.5.3

  • Update containerd (static binaries only) to v2.2.4
  • Update Go runtime to 1.26.4
  • Update RootlessKit to v3.0.1
Fixed 40

v29.8.0

  • Fix docker network inspect failing to find a healthy Swarm network when another Swarm network could not be allocated
  • Fix a node gossiping a superseded value for a Swarm service discovery entry after concurrent updates to the same key
  • Fix Swarm service names failing to resolve on a node indefinitely after it misses a network membership announcement
  • Fix Swarm service names failing to resolve on healthy nodes after a transient node failure
  • Prevent dockerd from hanging when the nft command produces enough stderr output to fill its pipe
  • Fix --disable-host-loopback not being enforced for the pasta network driver in rootless mode
  • Fix docker image inspect reporting a smaller image size than docker image ls with containerd image store
  • Fix slower image pulls caused by repeated registry authentication within a single pull with containerd image store

v29.7.2

  • Fix docker service create and docker service update panicking when the same environment variable is passed more than once
  • Fix a regression introduced in Docker Engine 29.7.0 that caused image pulls to reject images containing absolute hardlink targets
  • Fix a regression introduced in Docker Engine 29.7.0 that could cause image pulls and docker cp to fail on older Linux kernels when applying file permissions

v29.7.1

  • Fix a regression that prevented pulling images whose layers contain directories without explicit parent directory entries
  • Fix a regression where the CopyToContainer rejects container paths that traverse absolute symlinks, such as /var/run -> /run

v29.7.0

  • Fix a daemon panic when cleanup of a container's network interface fails while the container is being disconnected from a network
  • Fix a daemon panic when removing swarm ingress ports after failing to bind an ingress proxy listener
  • Keep the cgroup mount for containers with --net=host
  • containerd image store: Fix daemon-wide concurrent download and upload limits for pulls and pushes not being honored
  • Fix docker cp -a using the wrong file owner when copying files into containers with user namespace remapping enabled
  • Fix docker cp from a Windows container silently returning a file instead of an error when the source path ends with a separator but is not a directory
  • Fix docker stats reporting all zeros for running Windows containers when using the containerd runtime
  • Fix docker stats reporting empty network stats for running Windows containers when using the containerd runtime
  • Fix a typo in the docker create --pull flag description
  • Fix Swarm service updates failing due to file exists errors when a VIP IP alias already exists on the LB endpoint interface
  • Fix Swarm tasks being rejected when their image could not be pulled from the registry but was already present on the node
  • Prevent live-restored volumes from retaining active mount references when containers exit during daemon startup
  • Suppress the No such container error when docker rm --force succeeds for a nonexistent container

v29.6.0

  • docker image push now respects NO_COLOR
  • Fix docker system prune with containerd image store to include unpacked image data when reporting reclaimed space
  • Fix docker system df image size reporting to count only snapshots directly used by images
  • Fix registry authentication failures during worker image pulls being reported as misleading 'No such image' error
  • Fix default BuildKit GC policy to prune reproducible cache types as intended
  • Fix explicit file modes being filtered by the daemon umask, including COPY --chmod permissions
  • Fix image selection with the containerd image store on amd64 hosts when images provide amd64 variant-specific manifests
  • Don't publish container ports on host ports listed in net.ipv4.ip_local_reserved_ports when dynamically allocating ports
  • Fix a race condition in overlay network bulk sync that caused approximately 30 second DNS resolution delays on newly joined swarm nodes
  • Silence the spurious warning 'IPv4 forwarding is disabled' in rootless mode

v29.5.3

  • Reduce docker system df errors when images are pruned at the same time with the containerd image store
  • Fix AWS IMDS access with gvisor-tap-vsock and UDP port forwarding for non-loopback clients
  • Fix installation of plugins that require host networking

v29.5.2

  • Fix docker cp failing with "mkdirat: file exists" when a container has a bind mount whose target traverses an in-container symlink
Deprecated 1

v29.6.0

  • The Engine now returns a deprecation warning when a container connected to the default bridge is created with links specified
Security 10

v29.8.0

  • Add daemon support for configuring the default container AppArmor profile template
  • Prevent containers from using the 32-bit socketcall(2) path to create AF_VSOCK sockets and communicate with host virtual machines by adding AppArmor and SELinux policy rules

v29.7.0

  • Update github.com/moby/go-archive to v0.3.0 to fix CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h

v29.6.2

  • Fix CVE-2026-15793: Git source checkout from a bundle file could lead to command injection
  • Fix CVE-2026-15792: Incorrect parameters sent from a frontend could cause a panic
  • Fix CVE-2026-15791: An LLB file operation could be tricked into removing the contents of the /tmp directory
  • Fix CVE-2026-15789: A malicious client could bypass destination directory validation when uploading local sources
  • Fix CVE-2026-15788: A WCOW cache mount source selector could resolve NTFS junctions outside of the cache root

v29.6.1

  • Fix a vulnerability where a malicious image could supply a malicious /etc/passwd or /etc/group-style file causing excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions
  • Fix a vulnerability where a custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement

Original release notes, newest first

The list above is our reading of these notes; the originals from Docker are here, one fold per release.

v29.8.0v29.8.0
29.8.0

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

New
  • Add HostConfig.Umask option and a corresponding --umask <octal> flag to docker create/docker run to set the umask for a container's main process, execs, and healthchecks. moby/moby#53463, docker/cli#7108
  • Add support for attaching service names, environments, and custom CloudWatch entity attributes to logs from the awslogs logging driver. moby/moby#52632
Security
Networking
  • Fix docker network inspect failing to find a healthy Swarm network when another Swarm network could not be allocated. moby/moby#53325
  • Fix a node gossiping a superseded value for a Swarm service discovery entry after concurrent updates to the same key. moby/moby#53479
  • Fix Swarm service names failing to resolve on a node indefinitely after it misses a network membership announcement. moby/moby#53437
  • Fix Swarm service names failing to resolve on healthy nodes after a transient node failure. moby/moby#53142
  • Prevent dockerd from hanging when the nft command produces enough stderr output to fill its pipe. moby/moby#53517
  • Reduce gossip traffic generated by a node that repeatedly disconnects and rejoins the cluster. moby/moby#53479
  • Remote network-driver plugins can now set the container-side interface name via the DstName field in their Join response. moby/moby#52866
  • Reserve network names "container" and "container:" to prevent creation of unusable networks. moby/moby#51973
  • Spread the daemon's periodic Swarm overlay network gossip and synchronization work over time, avoiding recurring bursts of CPU and network usage. moby/moby#53475
  • Swarm service-mesh published ports now use the same infrastructure as published ports for local containers. moby/moby#53118
Rootless
  • Fix --disable-host-loopback not being enforced for the pasta network driver in rootless mode. moby/moby#53358
  • Update RootlessKit to v3.1.0, adding support for the pesto port driver in rootless mode. Set DOCKERD_ROOTLESS_ROOTLESSKIT_PORT_DRIVER=pesto to use it; it requires the pasta network driver and supports IPv4 only. moby/moby#53358
Go SDK
Bug fixes and enhancements
  • Add annotation filter to container listings (docker ps, GET /containers/json) allowing to filter containers by their annotations. moby/moby#53538
  • containerd image store: Fix docker image inspect reporting a smaller image size than docker image ls. moby/moby#53426
  • containerd image store: Fix slower image pulls caused by repeated registry authentication within a single pull. moby/moby#53497
  • Do not log expected image signature identity misses as errors for containerd image store images. moby/moby#53495
  • dockerd now uses the embedded containerd if no system containerd service is configured and containerd is not installed. moby/moby#53388
  • Fix GET /images/{name}/json not including unpacked snapshot usage in Size when using the containerd image store. moby/moby#53426
  • Fix classic-builder cache for Dockerfile stages that select a non-host platform with FROM --platform. moby/moby#53503
  • Fix CLI panic when DOCKER_HOST or -H specifies an invalid host. docker/cli#7280
  • Fix health checks being delayed for too long when the start interval is longer than the start period. moby/moby#52317
  • Fix inconsistent mount ordering in docker inspect output (GET /containers/{id}/json) and container listings (docker ps, GET /containers/json). moby/moby#53534
  • Fix NRI container metadata so Container.Args includes the resolved executable as argv[0], matching the process launched in the container instead of only the Docker Cmd. moby/moby#53423
  • Fix Swarm service creation failing when an automatically generated name is already in use. moby/moby#53468
  • Fix the container root directory / being world-writable when using the btrfs storage driver. moby/moby#53500
  • Fixed docker ps sorting published ports lexicographically instead of numerically. docker/cli#7144
  • Preserve service mount order during forced updates to avoid an unnecessary rollout on the next stack deploy. docker/cli#7227
  • Prevent containerd's v2 CRI plugins from loading when CRI is disabled. moby/moby#53564
  • Print plugin hook output (e.g. the "What's next:" hint) after the command's error message instead of before it. docker/cli#6976
  • Reject checkpoint IDs containing path separators to prevent access outside the container checkpoint directory. moby/moby#53377
Packaging updates

View originalPermalink

v29.7.2v29.7.2
29.7.2

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Bug fixes and enhancements
  • Fix docker service create and docker service update panicking when the same environment variable is passed more than once. docker/cli#7145
  • Fix a regression introduced in Docker Engine 29.7.0 that caused image pulls to reject images containing absolute hardlink targets, as produced by some image builders. moby/moby#53305
  • Fix a regression introduced in Docker Engine 29.7.0 that could cause image pulls and docker cp to fail on older Linux kernels when applying file permissions, including for device nodes. moby/moby#53305
Packaging updates
Networking
  • Improve compatibility with more nftables releases by terminating base-chain policies with a semicolon. moby/moby#53303

View originalPermalink

v29.7.1v29.7.1
29.7.1

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Bug fixes and enhancements
  • Fix a regression that prevented pulling images whose layers contain directories without explicit parent directory entries. moby/moby#53260
  • Fix a regression where the CopyToContainer rejects container paths that traverse absolute symlinks, such as /var/run -> /run. moby/moby#53261

View originalPermalink

v29.7.0v29.7.0
29.7.0

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

New
  • Add an experimental embedded-containerd feature that runs containerd inside the daemon process instead of as a separate managed process. moby/moby#52898
  • Mount type image is no longer experimental. moby/moby#52998
  • Add the default-stop-timeout daemon option to configure the stop timeout assigned to containers without an explicit timeout. moby/moby#53146
Security

This release includes a fix for a security vulnerability affecting Docker Engine and related components.

Networking
  • Fix a daemon panic when cleanup of a container's network interface fails while the container is being disconnected from a network. moby/moby#53237
  • Fix a daemon panic when removing swarm ingress ports after failing to bind an ingress proxy listener. moby/moby#53022
Rootless
Bug fixes and enhancements
  • Add shell completion for --filter names and known values to docker service ls, docker service ps, and docker node ps. docker/cli#7124
  • containerd image store: Fix daemon-wide concurrent download and upload limits for pulls and pushes not being honored. moby/moby#53081
    • To preserve the previous unlimited startup behavior, configure "max-concurrent-downloads" and "max-concurrent-uploads" to 0
  • Fix docker cp -a using the wrong file owner when copying files into containers with user namespace remapping enabled. moby/moby#53084
  • Fix docker cp from a Windows container silently returning a file instead of an error when the source path ends with a separator but is not a directory. moby/moby#53123
  • Fix docker stats reporting all zeros for running Windows containers when using the containerd runtime. moby/moby#53101
  • Fix docker stats reporting empty network stats for running Windows containers when using the containerd runtime. moby/moby#53219
  • Fix a typo in the docker create --pull flag description. docker/cli#7103
  • Fix Swarm service updates failing due to "file exists" errors when a VIP IP alias already exists on the LB endpoint interface. moby/moby#51657
  • Fix Swarm tasks being rejected when their image could not be pulled from the registry but was already present on the node. moby/moby#53212
  • Improve the error returned when a container hostname exceeds Linux's 64-byte limit. moby/moby#53121
  • Prevent live-restored volumes from retaining active mount references when containers exit during daemon startup. moby/moby#53115
  • Suppress the “No such container” error when docker rm --force succeeds for a nonexistent container. docker/cli#7110
Packaging updates

View originalPermalink

v29.6.2v29.6.2
29.6.2

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Security

This release includes fixes for multiple security vulnerabilities affecting Docker Engine.

  • CVE-2026-15793: Git source checkout from a bundle file could lead to command injection. GHSA-hw3h-2gp9-cxpv
  • CVE-2026-15792: Incorrect parameters sent from a frontend could cause a panic. GHSA-qx3x-mv6r-52p6
  • CVE-2026-15791: An LLB file operation could be tricked into removing the contents of the /tmp directory. GHSA-32pv-7hq5-qhwq
  • CVE-2026-15789: A malicious client could bypass destination directory validation when uploading local sources. GHSA-g2h8-426c-7976
  • CVE-2026-15788: A WCOW cache mount source selector could resolve NTFS junctions outside of the cache root. GHSA-388v-wmr2-g2v2
Packaging updates
Rootless

View originalPermalink

v29.6.1v29.6.1
29.6.1

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Security

This release includes fixes for multiple security vulnerabilities affecting Docker Engine.

  • A malicious image could supply a malicious /etc/passwd or /etc/group-style file causing excessive memory consumption, potentially resulting in process termination due to Out Of Memory (OOM) conditions. GHSA-mjcv-p78q-w5fw, GHSA-jpcc-p29g-p8mq, GHSA-72x6-4j93-7w86
  • A custom frontend could send a crafted build request that disabled Seccomp and AppArmor protections for the build container, even if the user did not explicitly allow the security.insecure entitlement. Other security measures, like Linux capabilities were still applied to these containers. GHSA-7236-3392-c5c6
Bug fixes and enhancements
Packaging updates

View originalPermalink

v29.6.0v29.6.0
29.6.0

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

New
  • POST /containers/{id}/update now supports per-device blkio resource settings. moby/moby#52651
  • Add GET /images/{name}/attestations endpoint to retrieve in-toto attestation statements (such as SLSA provenance and SPDX SBOM) attached to an image. Supports optional platform selection, predicate type filtering, and a statement query parameter for verbatim statement bodies.
Bug fixes and enhancements
  • docker image push now respects NO_COLOR. docker/cli#6957
  • containerd image store: Fix docker system prune to include unpacked image data when reporting reclaimed space. moby/moby#52905
  • Fix docker system df image size reporting to count only snapshots directly used by images. moby/moby#52901
  • Fix a bug where registry authentication failures during worker image pulls were reported as a misleading “No such image” error. moby/moby#52698
  • Fix default BuildKit GC policy to prune reproducible cache types as intended. moby/moby#52814
  • Fix explicit file modes being filtered by the daemon umask, including COPY --chmod permissions. moby/moby#52892
  • Fix image selection with the containerd image store on amd64 hosts when images provide amd64 variant-specific manifests. moby/moby#52773
  • The --password flag on docker login now accepts - to pass the password through STDIN as alternative to --password-stdin. docker/cli#7029
Packaging updates
Networking
  • Allow the nftables firewall mode to be used with a daemon that is linked against libnftables when the nft command is not installed on the system. moby/moby#52820
  • Don't publish container ports on host ports listed in net.ipv4.ip_local_reserved_ports when dynamically allocating ports. moby/moby#52818
  • Fix a race condition in overlay network bulk sync that caused ~30s DNS resolution delays on newly joined swarm nodes. moby/moby#52862
  • Mitigate a crash in libnftables when using nftables as the firewall backend by changing the default build option to execute the nft command instead. Users building dockerd from source can opt into linking against libnftables by building with the libnftables build tag. moby/moby#52886
Rootless
  • Silence the spurious warning "IPv4 forwarding is disabled". moby/moby#52742
Deprecations
  • The Engine now returns a deprecation warning when a container connected to the default bridge is created with links specified. moby/moby#47427

View originalPermalink

v29.5.3v29.5.3
29.5.3

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Bug fixes and enhancements
  • Reduce docker system df errors when images are pruned at the same time with the containerd image store. moby/moby#52672
Packaging updates
Rootless
  • Fix AWS IMDS access with gvisor-tap-vsock and UDP port forwarding for non-loopback clients. moby/moby#52710
  • Fix installation of plugins that require host networking. moby/moby#52735

View originalPermalink

v29.5.2v29.5.2
29.5.2

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Bug fixes and enhancements
  • Fix docker cp failing with "mkdirat: file exists" when a container has a bind mount whose target traverses an in-container symlink (e.g. /var/run -> /run). moby/moby#52655

View originalPermalink