25.0.19

Release date

Name

Upstream release

2026-OCT-05

MCR 25.0.19

Moby 25.0.18 and Docker CLI 25.0.7

Highlights

Enhancement

Detail

FIPS packages built with the Go Cryptographic Module

The +fips package variants are now built against the Go Cryptographic Module, validated by SafeLogic as CryptoComply Native Go (CMVP certificate #5349). Non-FIPS packages are unaffected.

The libcrypto3-mirantis package is no longer needed or used, and can be safely removed after the MCR 25.0.19 update.

Changelog

MCR 25.0.19 comprises the Moby 25.0.19 upstream release. Changes specific to this version of MCR include:

  • The +fips packages are built with the Go Cryptographic Module (CryptoComply Native Go, CMVP #5349) instead of the Mirantis-patched Go toolchain, and libcrypto3-mirantis is no longer required.

  • Toolchain, in the style of the 25.0.18 changelog line: stock Go 1.26.6 with the Go Cryptographic Module for FIPS, with runc built on Go 1.26.7.

  • Windows: the Docker CLI no longer searches %ProgramData%\Docker\cli-plugins for plugins (CVE-2025-15558).

  • The Docker CLI now negotiates the ML-KEM hybrid (post-quantum) TLS key-exchange groups, matching the daemon. Previously the CLI’s build settings disabled them.

  • The engine picks up the three upstream 25.0-branch pull requests:

  • Fixes backported ahead of an upstream release:

    • docker cp with nested bind mounts (moby/moby#53725; merged on the upstream 25.0 branch, not yet in a release).

    • Two security fixes; refer to Security below.

Security

MCR 25.0.19 release mitigates several CVEs that affect MCR container images. Click the dropdown link below for comprehensive details.

CVEs Resolved

CVE

Image mitigated

Problem details from upstream

CVE-2026-56865

  • mcr/scanning-containerd.io-minimal

  • mcr/scanning-docker-ee

A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist attacker-controlled module content to a local Go module cache. This attack allows for a malicious GOPROXY to serve malicious module content that cannot be detected by evaluating the transparency log. All tiles are now correctly verified against their parents. In order to determine if you have been affected: rm -r go.sum go.work. sum vendor/&& go mod tidy

CVE-2026-56852

  • mcr/scanning-containerd.io-ctr

  • mcr/scanning-containerd.io-minimal

  • mcr/scanning-containerd.io-shim-crun

  • mcr/scanning-containerd.io-shim-runc

  • mcr/scanning-docker-compose-plugin-ee

  • mcr/scanning-docker-ee

  • mcr/scanning-docker-ee-cli

A norm.Iter can enter an infinite loop when handling input containing invalid UTF-8 bytes.

CVE-2026-46600

  • mcr/scanning-containerd.io-ctr

  • mcr/scanning-containerd.io-minimal

  • mcr/scanning-containerd.io-shim-crun

  • mcr/scanning-containerd.io-shim-runc

  • mcr/scanning-docker-compose-plugin-ee

  • mcr/scanning-docker-ee

  • mcr/scanning-docker-ee-cli

  • mcr/scanning-docker-ee-rootless-extras

Parsing an invalid SVCB or HTTPS RR can panic when the size of a parameter value overflows the message buffer.

CVE-2025-52881

  • mcr/scanning-docker-ee-cli

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7, 1.3.2 and 1.4.0-rc.2, an attacker can trick runc into misdirecting writes to /proc to other procfs files through the use of a racing container with shared mounts (we have also verified this attack is possible to exploit using a standard Dockerfile with docker buildx build as that also permits triggering parallel execution of containers with custom shared mounts configured). This redirect could be through symbolic links in a tmpfs or theoretically other methods such as regular bind-mounts. While similar, the mitigation applied for the related CVE, CVE-2019-19921, was fairly limited and effectively only caused runc to verify that when LSM labels are written they are actually procfs files. This issue is fixed in versions 1.2.8, 1.3.3, and 1.4. 0-rc.3.

CVE-2025-52565

  • mcr/scanning-docker-ee-cli

runc is a CLI tool for spawning and running containers according to the OCI specification. Versions 1.0.0-rc3 through 1.2.7, 1.3.0-rc.1 through 1.3.2, and 1.4.0-rc.1 through 1.4.0-rc.2, due to insufficient checks when bind-mounting /dev/pts/$n to /dev/console inside the container, an attacker can trick runc into bind-mounting paths which would normally be made read-only or be masked onto a path that the attacker can write to. This attack is very similar in concept and application to CVE-2025-31133, except that it attacks a similar vulnerability in a different target (namely, the bind-mount of /dev/pts/$n to /dev/console as configured for all containers that allocate a console). This happens after pivot_root(2), so this cannot be used to write to host files directly – however, as with CVE-2025-31133, this can load to denial of service of the host or a container breakout by providing the attacker with a writable copy of /proc/sysrq-trigger or /proc/sys/kernel/core_pattern (respectively). This issue is fixed in versions 1.2.8, 1.3.3 and 1.4.0-rc.3.

CVE-2025-31133

  • mcr/scanning-docker-ee-cli

runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, 1.3.0-rc.1 through 1.3.1, 1.4.0-rc.1 and 1.4.0-rc.2 files, runc would not perform sufficient verification that the source of the bind-mount (i.e., the container’s /dev/null) was actually a real /dev/null inode when using the container’s /dev/null to mask. This exposes two methods of attack: an arbitrary mount gadget, leading to host information disclosure, host denial of service, container escape, or a bypassing of maskedPaths. This issue is fixed in versions 1.2.8, 1. 3.3 and 1.4.0-rc.3.

CVE-2024-24557

  • mcr/scanning-docker-ee-cli

Moby is an open-source project created by Docker to enable software containerization. The classic builder cache system is prone to cache poisoning if the image is built FROM scratch. Also, changes to some instructions (most important being HEALTHCHECK and ONBUILD) would not cause a cache miss. An attacker with the knowledge of the Dockerfile someone is using could poison their cache by making them pull a specially crafted image that would be considered as a valid cache candidate for some build steps. 23.0+ users are only affected if they explicitly opted out of Buildkit (DOCKER_BUILDKIT=0 environment variable) or are using the /build API endpoint. All users on versions older than 23.0 could be impacted. Image build API endpoint (/build) and ImageBuild function from github.com/docker/docker/client is also affected as it the uses classic builder by default. Patches are included in 24.0.9 and 25.0.2 releases.

GitHub milestones

The GitHub milestones offer full detail on the pull requests and changes as they correlate to the upstream Moby 25.0.18 release:

Major component versions

Version detail for the major components that comprise MCR 25.0.19 is presented in the table below:

Component

Upstream Version

Mirantis Version

Moby

25.0.19

25.0.19m1

Docker CLI

25.0.7

25.0.7m10

containerd (Linux)

1.7.35

1.7.35m2

containerd (Windows)

1.6.39

1.6.39m2

runc

1.4.3

1.4.3m1

crun

1.27.1

–

cri-dockerd

0.4.4

0.4.4

buildx

0.12.1

0.12.2-m3

Go runtime

go1.26.6

buildkit

–

0.12.6-m.3

Docker Compose CLI plugin

2.40.3

2.40.4m2

Platform test detail

Platform

Kernel tested

Oracle Linux 8.10

4.18.0-553.164.1.el8_10.x86_64

RHEL 10.2

6.12.0-211.61.1.el10_2.x86_64

RHEL 9.8

5.14.0-687.45.1.el9_8.x86_64

RHEL 9.6

5.14.0-570.141.1.el9_6.x86_64

RHEL 8.10

4.18.0-553.158.1.el8_10.x86_64

Rocky 8.10

4.18.0-553.137.1.el8_10.x86_64

SLES15 SP7

6.4.0-150700.53.81-default

Ubuntu 24.04

7.0.0-1013-aws

Ubuntu 22.04

6.8.0-1066-aws

Windows 2022 Core

10.0 20348