Sourced from github.com/docker/docker's releases.
v20.10.27
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug Fixes and Enhancements
- Fix dockerd-rootless-setuptools.sh when user name contains a backslash. moby/moby#46424
- Add
IP_NF_MANGLE
to check-config.sh to the "generally required" list in check-config.sh because it is required by Swarm. moby/moby#46674- Fix a deadlock in libnetwork which could prevent containers from starting. moby/moby#46693
- Write overlay2 layer metadata atomically. moby/moby#46705
- Support building with Go 1.20. moby/moby#46694 moby/moby#46695 moby/moby#46696
Packaging Updates
- Update to go1.20.10, golang/org/x/net v0.17.0. moby/moby#46692
Security
- Deny containers access to
/sys/devices/virtual/powercap
by default. This change hardens against CVE-2020-8694, CVE-2020-8695, and CVE-2020-12912, and an attack known as the PLATYPUS attack. For more details, see advisory, commit.v20.10.26
20.10.26
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones:
Bug Fixes and Enhancements
- Support filesystems which do not support extended file attributes with the VFS graph driver. moby/moby#45466
- Fix AppArmor profile docker-default
/proc/sys
rule. moby/moby#45716- seccomp: always allow
name_to_handle_at(2)
. moby/moby#45835- Fix an issue which prevented volumes mounted to a live-restored container from being removed. moby/moby#45840
- client: resolve an incompatibility with Go 1.20.6, Go 1.20.7, Go 1.19.11 and Go 1.19.12. moby/moby#45972
- windows: fix
--register-service
when executed from within binary directory. moby/moby#46217Packaging Updates
- Update Go to 1.19.12. moby/moby#46142
- Update containerd to v1.6.22. moby/moby#46105
- Update runc to v1.1.8. moby/moby#46031
- Delete Upstart init scripts and clean up sysvinit. moby/moby#46047
v20.10.25
Bug fixes and enhancements
- Fix log loss with the AWSLogs log driver moby/moby#45349
... (truncated)
81ebe71
Merge pull request from GHSA-jq35-85cj-fj4pfb63665
Merge pull request #46705 from thaJeztah/20.10_backport_atomic-layer-data-writeb967d89
Merge pull request #46692 from corhere/backport-20.10/update-x-net-v0.172c22bd5
vendor: golang.org/x/net v0.17.0d862c21
Update to go1.20.10cb47414
Merge pull request #46696 from corhere/backport-20.10/go1.20-enablementea4eb73
Merge pull request #46695 from corhere/backport-20.10/safer-fileinfo6c523aa
hack: fix suppressing Xattrs lint errors31b8374
pkg/archive: audit gosec file-traversal lints8e44855
Remove local fork of archive/tar package