-
Notifications
You must be signed in to change notification settings - Fork 27
Update module github.com/docker/docker to v28 [SECURITY] #222
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update module github.com/docker/docker to v28 [SECURITY] #222
Conversation
8663af6 to
437711e
Compare
fb4ce64 to
437711e
Compare
jbw976
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
looks like a bunch of the CI is failing, let me see if i can manually fix
Signed-off-by: Jared Watts <[email protected]>
437711e to
0531e4c
Compare
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
…bufbuild/buf to v1.59.0 - we need github.com/docker/docker to be v28.x+ to fix CVE - github.com/bufbuild/buf needs to be updated to be compatible with newer docker version Signed-off-by: Jared Watts <[email protected]>
jbw976
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
sweet, all checks are passing now, this now looks good! note that we had to bump github.com/bufbuild/buf also, because the previous version we were using is not compatible with the new docker bump.
This PR contains the following updates:
v27.2.1+incompatible->v28.0.0+incompatibleGitHub Vulnerability Alerts
CVE-2025-54410
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as moby/moby is commonly referred to as Docker, or Docker Engine.
Firewalld is a daemon used by some Linux distributions to provide a dynamically managed firewall. When Firewalld is running, Docker uses its iptables backend to create rules, including rules to isolate containers in one bridge network from containers in other bridge networks.
Impact
The iptables rules created by Docker are removed when firewalld is reloaded using, for example "firewall-cmd --reload", "killall -HUP firewalld", or "systemctl reload firewalld".
When that happens, Docker must re-create the rules. However, in affected versions of Docker, the iptables rules that isolate containers in different bridge networks from each other are not re-created.
Once these rules have been removed, containers have access to any port, on any container, in any non-internal bridge network, running on the Docker host.
Containers running in networks created with
--internalor equivalent have no access to other networks. Containers that are only connected to these networks remain isolated after a firewalld reload.Where Docker Engine is not running in the host's network namespace, it is unaffected. Including, for example, Rootless Mode, and Docker Desktop.
Patches
Moby releases 28.0.0 and newer are not affected. A fix is available in moby release 25.0.13.
Workarounds
After reloading firewalld, either:
References
https://firewalld.org/
https://firewalld.org/documentation/howto/reload-firewalld.html
Moby firewalld reload removes bridge network isolation in github.com/docker/docker
CVE-2025-54410 / GHSA-4vq8-7jfc-9cvp / GO-2025-3829
More information
Details
Moby firewalld reload removes bridge network isolation in github.com/docker/docker
Severity
Unknown
References
This data is provided by OSV and the Go Vulnerability Database (CC-BY 4.0).
Moby firewalld reload removes bridge network isolation
CVE-2025-54410 / GHSA-4vq8-7jfc-9cvp / GO-2025-3829
More information
Details
Moby is an open source container framework developed by Docker Inc. that is distributed as Docker Engine, Mirantis Container Runtime, and various other downstream projects/products. The Moby daemon component (dockerd), which is developed as moby/moby is commonly referred to as Docker, or Docker Engine.
Firewalld is a daemon used by some Linux distributions to provide a dynamically managed firewall. When Firewalld is running, Docker uses its iptables backend to create rules, including rules to isolate containers in one bridge network from containers in other bridge networks.
Impact
The iptables rules created by Docker are removed when firewalld is reloaded using, for example "firewall-cmd --reload", "killall -HUP firewalld", or "systemctl reload firewalld".
When that happens, Docker must re-create the rules. However, in affected versions of Docker, the iptables rules that isolate containers in different bridge networks from each other are not re-created.
Once these rules have been removed, containers have access to any port, on any container, in any non-internal bridge network, running on the Docker host.
Containers running in networks created with
--internalor equivalent have no access to other networks. Containers that are only connected to these networks remain isolated after a firewalld reload.Where Docker Engine is not running in the host's network namespace, it is unaffected. Including, for example, Rootless Mode, and Docker Desktop.
Patches
Moby releases 28.0.0 and newer are not affected. A fix is available in moby release 25.0.13.
Workarounds
After reloading firewalld, either:
References
https://firewalld.org/
https://firewalld.org/documentation/howto/reload-firewalld.html
Severity
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
docker/docker (github.com/docker/docker)
v28.0.0+incompatibleCompare Source
v27.5.1+incompatibleCompare Source
v27.5.0+incompatibleCompare Source
v27.4.1+incompatibleCompare Source
v27.4.0+incompatibleCompare Source
v27.3.1+incompatibleCompare Source
v27.3.0+incompatibleCompare Source
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.