Sitelet https://github.com/docker/docs/pull/26309/files
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
53 changes: 53 additions & 0 deletions content/manuals/engine/release-notes/29.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,59 @@ For more information about:
- Deprecated and removed features, see [Deprecated Engine Features](../deprecated.md).
- Changes to the Engine API, see [Engine API version history](/reference/api/engine/version-history/).

## 29.9.0

{{< release-date date="2026-10-08" >}}

For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:

- [docker/cli, 29.9.0 milestone](https://github.com/docker/cli/issues?q=is%3Aclosed+milestone%3A29.9.0)
- [moby/moby, 29.9.0 milestone](https://github.com/moby/moby/issues?q=is%3Aclosed+milestone%3A29.9.0)

### Security

The Go runtime update fixes the following security vulnerabilities in Docker Engine:

- **CVE-2026-97032**: An HTTP/2 client could crash the daemon by changing the HPACK header table size while sending requests. [golang/go#81867](https://go.dev/issue/81867)
- **CVE-2026-78659**: An HTTP/2 client could exhaust daemon memory by declaring a large number of fields in a `Trailer` header, bypassing the header size limits. [golang/go#81857](https://go.dev/issue/81857)
- **CVE-2026-78663**: An HTTP/2 client could bypass the connection-level flow control limit by resetting streams, making the daemon buffer more request data than the limit allows. [golang/go#81743](https://go.dev/issue/81743)
- **CVE-2026-78669**: An HTTP/2 client could cause excessive daemon CPU use by opening many streams and repeatedly changing the initial window size. [golang/go#81742](https://go.dev/issue/81742)
- **CVE-2026-56857**: On Windows, the daemon could create a directory outside its data root if someone with write access to the data root had placed a junction there. [golang/go#81739](https://go.dev/issue/81739)

The `golang.org/x/net` update to v0.60.0 applies the same HTTP/2 fixes to the deprecated `/grpc` endpoint and to the gRPC server that BuildKit runs for frontend containers, such as images referenced by a `# syntax=` directive.

### Bug fixes and enhancements

- containerd image store: Add the `lazy-pull` daemon feature to control whether `docker pull` skips downloading layer content that the snapshotter already provides. Lazy pulls are enabled by default for known remote snapshotters (`nydus`, `overlaybd`, `soci`, `stargz`). [moby/moby#53877](https://github.com/moby/moby/pull/53877)
- containerd image store: Fix pulls skipping required layer blobs when unpacked layers already exist, leaving images runnable but incomplete for export or push. [moby/moby#53615](https://github.com/moby/moby/pull/53615)
- Fix `docker container create --name` reporting a misleading validation error mentioning invalid characters instead of invalid name length. [moby/moby#53484](https://github.com/moby/moby/pull/53484)
- Fix a connection leak to the RootlessKit API socket on every `GET /version` request in rootless mode. [moby/moby#53836](https://github.com/moby/moby/pull/53836)
- Improve Windows service registration and unregistration cleanup, including making service unregistration (`--unregister-service`) idempotent. [moby/moby#53845](https://github.com/moby/moby/pull/53845)

### Packaging updates

- Update BuildKit to [v0.34.0](https://github.com/moby/buildkit/releases/tag/v0.34.0). [moby/moby#53882](https://github.com/moby/moby/pull/53882)
- Update Go runtime to [1.26.9](https://go.dev/doc/devel/release#go1.26.9). [docker/cli#7363](https://github.com/docker/cli/pull/7363)
- Update containerd (static binaries) to [v2.4.1](https://github.com/containerd/containerd/releases/tag/v2.4.1). [moby/moby#53773](https://github.com/moby/moby/pull/53773)

### Networking

- Allow IPv6 Neighbour Discovery between containers on a bridge network with inter-container communication disabled, matching the existing IPv4 behaviour. [moby/moby#53723](https://github.com/moby/moby/pull/53723)
- Fix `docker ps` and `GET /containers/json` omitting published ports for networks using routed gateway mode. [moby/moby#53693](https://github.com/moby/moby/pull/53693)
- Fix a bug where a restarted daemon could be dropped from a peer's service discovery and load balancing until it rejoined the gossip cluster. [moby/moby#53688](https://github.com/moby/moby/pull/53688)
- Fix a published port being unreachable from another container on the same network when inter-container communication is disabled, including Swarm services published through the routing mesh. [moby/moby#53723](https://github.com/moby/moby/pull/53723)
- Fix an issue where errors programming the kernel to encrypt the overlay network data-plane could in some circumstances lead to encrypted-overlay-network traffic to some nodes being transmitted in cleartext. As the receiving peer would drop cleartext packets for encrypted overlay networks as spoofed, the loss of confidentiality is limited to unidirectional flows (e.g. UDP DNS queries) and handshake attempts that never proceed (e.g. TCP SYN). [moby/moby#53420](https://github.com/moby/moby/pull/53420)
- Fix connecting live-restored containers with an implicit `host-gateway` mapping to additional networks. [moby/moby#53093](https://github.com/moby/moby/pull/53093)
- Fix overlay peers becoming unreachable after a node rejoins the cluster or a service is redeployed, when the VXLAN device had already learned a dynamic FDB entry for the peer. [moby/moby#53663](https://github.com/moby/moby/pull/53663)
- Fix Swarm tasks on overlay networks being rejected when the daemon can't write to `/var/lib/docker`. [moby/moby#53848](https://github.com/moby/moby/pull/53848)
- Published Swarm-service ports are accessible at the host's IPv6 addresses when the userland proxy is enabled. A change introduced in v29.8.0 incidentally enabled this functionality; it is a tested and supported feature as of v29.9.0. [moby/moby#53727](https://github.com/moby/moby/pull/53727)
- Release a node's IPsec security associations and policies when the last container leaves an encrypted overlay network, instead of leaking them until the daemon restarts. [moby/moby#53420](https://github.com/moby/moby/pull/53420)
- Restore the logic to remove the empty `DOCKER-INGRESS` iptables chain, and the `FORWARD` rule that jumps to it, left behind by Docker Engine 28.0.0 and earlier. [moby/moby#53825](https://github.com/moby/moby/pull/53825)

### Rootless

- Update RootlessKit (3.2.0). [moby/moby#53607](https://github.com/moby/moby/pull/53607)

## 29.8.2

{{< release-date date="2026-09-30" >}}
Expand Down