Sourced from github.com/docker/docker's releases.
v25.0.6
25.0.6
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
- docker/cli, 25.0.6 milestone
- moby/moby, 25.0.6 milestone
- Deprecated and removed features, see Deprecated Features.
- Changes to the Engine API, see API version history.
Security
This release contains a fix for CVE-2024-41110 / GHSA-v23v-6jw2-98fq that impacted setups using authorization plugins (AuthZ) for access control.
Bug fixes and enhancements
- [25.0] remove erroneous
platform
from imageconfig
OCI descriptor indocker save
output. moby/moby#47695- [25.0 backport] Fix a nil dereference when getting image history for images having layers without the
Created
value set. moby/moby#47759- [25.0 backport] apparmor: Allow confined runc to kill containers. moby/moby#47830
- [25.0 backport] Fix an issue where rapidly promoting a Swarm node after another node was demoted could cause the promoted node to fail its promotion. moby/moby#47869
- [25.0 backport] don't depend on containerd platform.Parse to return a typed error. moby/moby#47890
- [25.0 backport] builder/mobyexporter: Add missing nil check moby/moby#47987
Packaging updates
- Update AWS SDK Go v2 to v1.24.1 for AWS CloudWatch logging driver. moby/moby#47724
- Update Go runtime to 1.21.12, which contains security fixes for CVE-2024-24791 moby/moby#48146
- Update Containerd (static binaries only) to v1.7.20. moby/moby#48199
Full Changelog: https://github.com/moby/moby/compare/v25.0.5...v25.0.6
v25.0.5
25.0.5
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
- docker/cli, 25.0.5 milestone
- moby/moby, 25.0.5 milestone
- Deprecated and removed features, see Deprecated Features.
- Changes to the Engine API, see API version history.
Security
This release contains a security fix for CVE-2024-29018, a potential data exfiltration from 'internal' networks via authoritative DNS servers.
Bug fixes and enhancements
CVE-2024-29018: Do not forward requests to external DNS servers for a container that is only connected to an 'internal' network. Previously, requests were forwarded if the host's DNS server was running on a loopback address, like systemd's 127.0.0.53. moby/moby#47589
plugin: fix mounting /etc/hosts when running in UserNS. moby/moby#47588
rootless: fix
open /etc/docker/plugins: permission denied
. moby/moby#47587Fix multiple parallel
docker build
runs leaking disk space. moby/moby#47527
... (truncated)
b08a51f
Merge pull request #48231
from austinvazquez/backport-vendor-otel-v0.46.1-to-...d151b0f
vendor: OTEL v0.46.1 / v1.21.0c6ba9a5
Merge pull request #48225
from austinvazquez/backport-workflow-artifact-reten...4673a3c
Merge pull request #48227
from austinvazquez/backport-backport-branch-check-t...30f8908
github/ci: Check if backport is opened against the expected branch7454d6a
ci: update workflow artifacts retention65cc597
Merge commit from forkb722836
Merge pull request #48199
from austinvazquez/update-containerd-binary-to-1.7.20e8ecb9c
update containerd binary to v1.7.20e6cae1f
update containerd binary to v1.7.19