Docker Engine (moby/moby) v25.0.17 Patch Release Addresses Multiple CVEs
securitysecurity-advisoryengineer
patch security
Docker Engine v25.0.17 is a patch release focused on critical security fixes. It resolves several vulnerabilities, including symlink escape issues during mount destination creation and `docker cp` operations, as well as decompressing archives before entering container filesystems. The update also vendors `containerd` v1.7.33 to mitigate an additional CVE. This release is crucial for users to enhance the security posture of their Docker environments.
Read the original announcement →
https://github.com/moby/moby/releases/tag/v25.0.17
Related releases
- Moby Project v25.0.16 Patches CVEs and Fixes Image Store Bug Docker Engine Releases ·
- Docker Engine 29.7.2 addresses panics, image pull regressions, and networking issues Docker Engine Releases ·
- Docker Compose v5.4.0 enhances resource reconciliation and fixes bugs Docker Compose Releases ·
- Docker v29.7.1 addresses image pull and CopyToContainer regressions Docker Engine Releases ·
- Docker 29.7.0: Embedded containerd, security fix, and numerous enhancements Docker Engine Releases ·
- Moby Client v0.5.1: Fixes for service platforms and query arguments Docker Engine Releases ·