Moby Project v25.0.16 Patches CVEs and Fixes Image Store Bug
infrasecurity-advisoryengineer
patch security
The Moby Project has released version 25.0.16 of its container engine, delivering crucial stability and security enhancements. This patch addresses a bug causing duplicate `PUT` requests during multi-platform image pushes in the containerd image store. Critical dependency updates are included, specifically replacing `github.com/moby/buildkit` with `github.com/Mirantis/buildkit v0.12.6-m.1`, to remediate several identified CVEs. These updates reinforce the reliability of image management and bolster the Moby engine's overall security posture.
Read the original announcement →
https://github.com/moby/moby/releases/tag/v25.0.16
Related releases
- Docker Engine (moby/moby) v25.0.17 Patch Release Addresses Multiple CVEs Docker Engine Releases ·
- Docker Engine 29.7.2 addresses panics, image pull regressions, and networking issues Docker Engine Releases ·
- Docker Compose v5.4.0 enhances resource reconciliation and fixes bugs Docker Compose Releases ·
- Docker v29.7.1 addresses image pull and CopyToContainer regressions Docker Engine Releases ·
- Docker 29.7.0: Embedded containerd, security fix, and numerous enhancements Docker Engine Releases ·
- Moby Client v0.5.1: Fixes for service platforms and query arguments Docker Engine Releases ·