| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| README.md | 2026-09-30 | 4.6 kB | |
| v29.8.2 source code.tar.gz | 2026-09-30 | 22.2 MB | |
| v29.8.2 source code.zip | 2026-09-30 | 30.5 MB | |
| Totals: 3 Items | 52.7 MB | 2 | |
29.8.2
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Security
This release fixes the following security vulnerabilities in Docker Engine:
- CVE-2026-53493: Pulling a crafted OCI image index with deeply nested or widely fanned-out descriptors could cause unbounded CPU and memory use. GHSA-pg57-6jwg-q645
- CVE-2026-92543: A malicious DNS response could make registry connections skip TLS certificate verification or fall back to HTTP, exposing registry credentials or allowing image substitution. GHSA-7cfq-22r6-qp73
- CVE-2026-92542: Unprivileged users on a Swarm node could inject forged Ethernet frames into encrypted overlay networks on peer nodes. GHSA-6m9p-4h64-m6vh
The BuildKit update fixes the following security vulnerabilities:
- CVE-2026-93315: A build step could redirect proxy CA cleanup outside the build root filesystem, block it with a special file, or let the build succeed when cleanup failed. GHSA-2f5p-x9ph-g97x
- CVE-2026-93316: A build that requested CDI devices could cause a daemon panic when CDI support was disabled, for example with
"features": {"cdi": false}indaemon.json. GHSA-r456-g3gm-cvxf - CVE-2026-93317: With the containerd image store, a client using the low-level LLB API could poison the build cache with container blob contents that did not match their claimed digest. GHSA-p3rc-w3hc-pqvv
- CVE-2026-93318: A malicious image could poison the build cache with layer DiffIDs that did not match the actual layer contents. GHSA-f2v9-hprr-32q3
- CVE-2026-93319: A malicious external frontend could crash the daemon through gateway container lifecycle races or malformed requests and definitions. GHSA-4hgw-qrhw-fhg8
- CVE-2026-93320: Daemon-side snapshot reads and LLB
mkfileoperations did not safely handle special files. GHSA-9728-qjrv-2xh2 - CVE-2026-93321: A malformed LLB file operation with invalid symlink owner inputs could crash the daemon. GHSA-fjj4-h6vf-m9hj
- CVE-2026-93322: A malformed LLB merge operation with mismatched input counts could crash the daemon. GHSA-cv6p-7w7g-xjwq
- CVE-2026-93323: An oversized Dockerfile,
.dockerignore, gateway file, or nested LLB definition could exhaust daemon memory. GHSA-mgqf-486f-49vp - CVE-2026-93326: A crafted Git build source could bypass source policy rules that match on the repository URL, through a Git bundle locator or a full remote URL that did not match the source identifier. GHSA-66hf-6vf5-87hc
Bug fixes and enhancements
- Fix
docker cpfailing on a container with a bind-mounted socket nested inside another bind mount. [#53724] - Fix
docker infofailing with an “invalid Prefix” error after reloading a daemon with custom default address pools. [#53812]