Download Latest Version api_v1.56.1 source code.zip (30.7 MB) Google Add to Preferred Sources
Home / docker-v29.8.2
Name Modified Size InfoDownloads / Week
Parent folder
README.md 2026-09-30 4.6 kB
v29.8.2 source code.tar.gz 2026-09-30 22.2 MB
v29.8.2 source code.zip 2026-09-30 30.5 MB
Totals: 3 Items   52.7 MB 2

29.8.2

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

Security

This release fixes the following security vulnerabilities in Docker Engine:

  • CVE-2026-53493: Pulling a crafted OCI image index with deeply nested or widely fanned-out descriptors could cause unbounded CPU and memory use. GHSA-pg57-6jwg-q645
  • CVE-2026-92543: A malicious DNS response could make registry connections skip TLS certificate verification or fall back to HTTP, exposing registry credentials or allowing image substitution. GHSA-7cfq-22r6-qp73
  • CVE-2026-92542: Unprivileged users on a Swarm node could inject forged Ethernet frames into encrypted overlay networks on peer nodes. GHSA-6m9p-4h64-m6vh

The BuildKit update fixes the following security vulnerabilities:

  • CVE-2026-93315: A build step could redirect proxy CA cleanup outside the build root filesystem, block it with a special file, or let the build succeed when cleanup failed. GHSA-2f5p-x9ph-g97x
  • CVE-2026-93316: A build that requested CDI devices could cause a daemon panic when CDI support was disabled, for example with "features": {"cdi": false} in daemon.json. GHSA-r456-g3gm-cvxf
  • CVE-2026-93317: With the containerd image store, a client using the low-level LLB API could poison the build cache with container blob contents that did not match their claimed digest. GHSA-p3rc-w3hc-pqvv
  • CVE-2026-93318: A malicious image could poison the build cache with layer DiffIDs that did not match the actual layer contents. GHSA-f2v9-hprr-32q3
  • CVE-2026-93319: A malicious external frontend could crash the daemon through gateway container lifecycle races or malformed requests and definitions. GHSA-4hgw-qrhw-fhg8
  • CVE-2026-93320: Daemon-side snapshot reads and LLB mkfile operations did not safely handle special files. GHSA-9728-qjrv-2xh2
  • CVE-2026-93321: A malformed LLB file operation with invalid symlink owner inputs could crash the daemon. GHSA-fjj4-h6vf-m9hj
  • CVE-2026-93322: A malformed LLB merge operation with mismatched input counts could crash the daemon. GHSA-cv6p-7w7g-xjwq
  • CVE-2026-93323: An oversized Dockerfile, .dockerignore, gateway file, or nested LLB definition could exhaust daemon memory. GHSA-mgqf-486f-49vp
  • CVE-2026-93326: A crafted Git build source could bypass source policy rules that match on the repository URL, through a Git bundle locator or a full remote URL that did not match the source identifier. GHSA-66hf-6vf5-87hc

Bug fixes and enhancements

  • Fix docker cp failing on a container with a bind-mounted socket nested inside another bind mount. [#53724]
  • Fix docker info failing with an “invalid Prefix” error after reloading a daemon with custom default address pools. [#53812]

Packaging updates

Source: README.md, updated 2026-09-30