Docker 29.7.0: Embedded containerd, security fix, and numerous enhancements
securityinfrasecurity-advisory
security
Docker 29.7.0 introduces an experimental embedded containerd feature, moving it into the daemon process for potentially simpler management. This release also addresses a security vulnerability (CVE-2026-17106) affecting Docker Engine and related components, requiring updates for all users. Several bug fixes and enhancements are included, such as improved networking reliability and updates to underlying dependencies like Go and runc.
Security (1) ›
- Update github.com/moby/go-archive to v0.3.0 to fix CVE-2026-17106 / GHSA-hfg8-hc9c-6c3h. moby/moby#53247, docker/cli#7139
Read the original announcement →
https://github.com/moby/moby/releases/tag/docker-v29.7.0
Related releases
- Docker v29.7.1 addresses image pull and CopyToContainer regressions Docker Engine Releases ·
- Moby Client v0.5.1: Fixes for service platforms and query arguments Docker Engine Releases ·
- Docker Engine v29.6.2: Security fixes and dependency updates Docker Engine Releases ·
- Docker Compose v5.2.0 releases with new reconciliation algorithm Docker Compose Releases ·
- Docker Engine 29.6.1 addresses security vulnerabilities and updates components Docker Engine Releases ·
- Docker Compose v5.3.0 Adds Init Containers Docker Compose Releases ·