From 9d8d8f7e3f74a812a5f5726421d677c0d75e2620 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Pawe=C5=82=20Gronowski?= Date: Wed, 30 Sep 2026 17:35:20 +0200 Subject: [PATCH] engine: 29.8.2 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Signed-off-by: Paweł Gronowski --- content/manuals/engine/release-notes/29.md | 41 ++++++++++++++++++++++ hugo.yaml | 4 +-- 2 files changed, 43 insertions(+), 2 deletions(-) diff --git a/content/manuals/engine/release-notes/29.md b/content/manuals/engine/release-notes/29.md index c3f67b0a2a43..e8aaf1ad1400 100644 --- a/content/manuals/engine/release-notes/29.md +++ b/content/manuals/engine/release-notes/29.md @@ -22,6 +22,47 @@ For more information about: - Deprecated and removed features, see [Deprecated Engine Features](../deprecated.md). - Changes to the Engine API, see [Engine API version history](/reference/api/engine/version-history/). +## 29.8.2 + +{{< release-date date="2026-09-30" >}} + +For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: + +- [docker/cli, 29.8.2 milestone](https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A29.8.2) +- [moby/moby, 29.8.2 milestone](https://github.com/moby/moby/issues?q=is%3Aclosed+milestone%3A29.8.2) + +### Security + +This release fixes the following security vulnerabilities in Docker Engine: + +- **CVE-2026-53493**: Pulling a crafted OCI image index with deeply nested or widely fanned-out descriptors could cause unbounded CPU and memory use. [GHSA-pg57-6jwg-q645](https://github.com/containerd/containerd/security/advisories/GHSA-pg57-6jwg-q645) +- **CVE-2026-92543**: A malicious DNS response could make registry connections skip TLS certificate verification or fall back to HTTP, exposing registry credentials or allowing image substitution. [GHSA-7cfq-22r6-qp73](https://github.com/moby/moby/security/advisories/GHSA-7cfq-22r6-qp73) +- **CVE-2026-92542**: Unprivileged users on a Swarm node could inject forged Ethernet frames into encrypted overlay networks on peer nodes. [GHSA-6m9p-4h64-m6vh](https://github.com/moby/moby/security/advisories/GHSA-6m9p-4h64-m6vh) + +The BuildKit update fixes the following security vulnerabilities: + +- **CVE-2026-93315**: A build step could redirect proxy CA cleanup outside the build root filesystem, block it with a special file, or let the build succeed when cleanup failed. [GHSA-2f5p-x9ph-g97x](https://github.com/moby/buildkit/security/advisories/GHSA-2f5p-x9ph-g97x) +- **CVE-2026-93316**: A build that requested CDI devices could cause a daemon panic when CDI support was disabled, for example with `"features": {"cdi": false}` in `daemon.json`. [GHSA-r456-g3gm-cvxf](https://github.com/moby/buildkit/security/advisories/GHSA-r456-g3gm-cvxf) +- **CVE-2026-93317**: With the containerd image store, a client using the low-level LLB API could poison the build cache with container blob contents that did not match their claimed digest. [GHSA-p3rc-w3hc-pqvv](https://github.com/moby/buildkit/security/advisories/GHSA-p3rc-w3hc-pqvv) +- **CVE-2026-93318**: A malicious image could poison the build cache with layer DiffIDs that did not match the actual layer contents. [GHSA-f2v9-hprr-32q3](https://github.com/moby/buildkit/security/advisories/GHSA-f2v9-hprr-32q3) +- **CVE-2026-93319**: A malicious external frontend could crash the daemon through gateway container lifecycle races or malformed requests and definitions. [GHSA-4hgw-qrhw-fhg8](https://github.com/moby/buildkit/security/advisories/GHSA-4hgw-qrhw-fhg8) +- **CVE-2026-93320**: Daemon-side snapshot reads and LLB `mkfile` operations did not safely handle special files. [GHSA-9728-qjrv-2xh2](https://github.com/moby/buildkit/security/advisories/GHSA-9728-qjrv-2xh2) +- **CVE-2026-93321**: A malformed LLB file operation with invalid symlink owner inputs could crash the daemon. [GHSA-fjj4-h6vf-m9hj](https://github.com/moby/buildkit/security/advisories/GHSA-fjj4-h6vf-m9hj) +- **CVE-2026-93322**: A malformed LLB merge operation with mismatched input counts could crash the daemon. [GHSA-cv6p-7w7g-xjwq](https://github.com/moby/buildkit/security/advisories/GHSA-cv6p-7w7g-xjwq) +- **CVE-2026-93323**: An oversized Dockerfile, `.dockerignore`, gateway file, or nested LLB definition could exhaust daemon memory. [GHSA-mgqf-486f-49vp](https://github.com/moby/buildkit/security/advisories/GHSA-mgqf-486f-49vp) +- **CVE-2026-93326**: A crafted Git build source could bypass source policy rules that match on the repository URL, through a Git bundle locator or a full remote URL that did not match the source identifier. [GHSA-66hf-6vf5-87hc](https://github.com/moby/buildkit/security/advisories/GHSA-66hf-6vf5-87hc) + +### Bug fixes and enhancements + +- Fix `docker cp` failing on a container with a bind-mounted socket nested inside another bind mount. [moby/moby#53724](https://github.com/moby/moby/pull/53724) +- Fix `docker info` failing with an “invalid Prefix” error after reloading a daemon with custom default address pools. [moby/moby#53812](https://github.com/moby/moby/pull/53812) + +### Packaging updates + +- Update BuildKit to [v0.33.1](https://github.com/moby/buildkit/releases/tag/v0.33.1). [moby/moby#53823](https://github.com/moby/moby/pull/53823) +- Update containerd (static binaries) to [v2.3.6](https://github.com/containerd/containerd/releases/tag/v2.3.6). [moby/moby#53778](https://github.com/moby/moby/pull/53778) +- Update runc (in static binaries) to [v1.5.2](https://github.com/opencontainers/runc/releases/tag/v1.5.2). [moby/moby#53811](https://github.com/moby/moby/pull/53811) + ## 29.8.1 {{< release-date date="2026-09-15" >}} diff --git a/hugo.yaml b/hugo.yaml index 38dce8194f35..eb106816af64 100644 --- a/hugo.yaml +++ b/hugo.yaml @@ -175,10 +175,10 @@ params: # Latest version of the Docker Engine API latest_engine_api_version: "1.56" # Latest version of Docker Engine - docker_ce_version: "29.8.1" + docker_ce_version: "29.8.2" # Previous version of the Docker Engine # (Used to show e.g., "latest" and "latest"-1 in engine install examples - docker_ce_version_prev: "29.8.0" + docker_ce_version_prev: "29.8.1" # Latest Docker Compose version compose_version: "v5.5.0" # Latest BuildKit version