docker 29.9.0
v29.9.0
29.9.0
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Security
The Go runtime update fixes the following security vulnerabilities in Docker Engine:
- CVE-2026-97032: An HTTP/2 client could crash the daemon by changing the HPACK header table size while sending requests. golang/go#81867
- CVE-2026-78659: An HTTP/2 client could exhaust daemon memory by declaring a large number of fields in a
Trailerheader, bypassing the header size limits. golang/go#81857 - CVE-2026-78663: An HTTP/2 client could bypass the connection-level flow control limit by resetting streams, making the daemon buffer more request data than the limit allows. golang/go#81743
- CVE-2026-78669: An HTTP/2 client could cause excessive daemon CPU use by opening many streams and repeatedly changing the initial window size. golang/go#81742
- CVE-2026-56857: On Windows, the daemon could create a directory outside its data root if someone with write access to the data root had placed a junction there. golang/go#81739
The golang.org/x/net update to v0.60.0 applies the same HTTP/2 fixes to the deprecated /grpc endpoint and to the gRPC server that BuildKit runs for frontend containers, such as images referenced by a # syntax= directive.
Bug fixes and enhancements
- containerd image store: Add the
lazy-pulldaemon feature to control whetherdocker pullskips downloading layer content that the snapshotter already provides. Lazy pulls are enabled by default for known remote snapshotters (nydus,overlaybd,soci,stargz). moby/moby#53877 - containerd image store: Fix pulls skipping required layer blobs when unpacked layers already exist, leaving images runnable but incomplete for export or push. moby/moby#53615
- Fix
docker container create --namereporting a misleading validation error mentioning invalid characters instead of invalid name length. moby/moby#53484 - Fix a connection leak to the RootlessKit API socket on every
GET /versionrequest in rootless mode. moby/moby#53836 - Improve Windows service registration and unregistration cleanup, including making service unregistration (
--unregister-service) idempotent. moby/moby#53845
Packaging updates
- Update BuildKit to v0.34.0. moby/moby#53882
- Update Go runtime to 1.26.9. docker/cli#7363
- Update containerd (static binaries) to v2.4.1. moby/moby#53773
Networking
- Allow IPv6 Neighbour Discovery between containers on a bridge network with inter-container communication disabled, matching the existing IPv4 behaviour. moby/moby#53723
- Fix
docker psandGET /containers/jsonomitting published ports for networks using routed gateway mode. moby/moby#53693 - Fix a bug where a restarted daemon could be dropped from a peer's service discovery and load balancing until it rejoined the gossip cluster. moby/moby#53688
- Fix a published port being unreachable from another container on the same network when inter-container communication is disabled, including Swarm services published through the routing mesh. moby/moby#53723
- Fix an issue where errors programming the kernel to encrypt the overlay network data-plane could in some circumstances lead to encrypted-overlay-network traffic to some nodes being transmitted in cleartext. As the receiving peer would drop cleartext packets for encrypted overlay networks as spoofed, the loss of confidentiality is limited to unidirectional flows (e.g. UDP DNS queries) and handshake attempts that never proceed (e.g. TCP SYN). moby/moby#53420
- Fix connecting live-restored containers with an implicit
host-gatewaymapping to additional networks. moby/moby#53093 - Fix overlay peers becoming unreachable after a node rejoins the cluster or a service is redeployed, when the VXLAN device had already learned a dynamic FDB entry for the peer. moby/moby#53663
- Fix Swarm tasks on overlay networks being rejected when the daemon can't write to
/var/lib/docker. moby/moby#53848 - Published Swarm-service ports are accessible at the host's IPv6 addresses when the userland proxy is enabled. A change introduced in v29.8.0 incidentally enabled this functionality; it is a tested and supported feature as of v29.9.0. moby/moby#53727
- Release a node's IPsec security associations and policies when the last container leaves an encrypted overlay network, instead of leaking them until the daemon restarts. moby/moby#53420
- Restore the logic to remove the empty
DOCKER-INGRESSiptables chain, and theFORWARDrule that jumps to it, left behind by Docker Engine 28.0.0 and earlier. moby/moby#53825
Rootless
- Update RootlessKit (3.2.0). moby/moby#53607