25.0.9

Release date

Name

Upstream release

2025-MAR-10

MCR 25.0.9

Moby 25.0.9 and Docker CLI 25.0.9

Changelog

MCR 25.0.9 comprises the Moby 25.0.9 upstream release.

Changes specific to MCR

  • MCR contains the following component additions and updates:

    • crun support added as an alternative OCI runtime.

    • Fipster (Go runtime) go1.22.12-m1

Changes from upstream

The upstream pull requests detailed in the sections that follow are those that pertain to the MCR product. For the complete list of changes and pull requests upstream, refer to the GitHub milestones.

What is new

The MCR 25.0.9 patch release focuses on the delivery of CVE and bug fixes.

Security

go net/http: Fix CVE-2024-45336, The HTTP client drops sensitive headers after following a cross-domain redirect.

go crypto/x509: Fix CVE-2024-45341, A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain.

golang.org/x/net: Fix CVE-2024-45338, Non-linear parsing of case-insensitive content in golang.org/x/net/html

Bug fixes

containerd

runc

GitHub milestones

The GitHub milestones offer full detail on the pull requests and changes as they correlate to the upstream Moby 25.0.9 release:

Major component versions

Version detail for the major components that comprise MCR 25.0.9 is presented in the table below:

Component

Upstream Version

Mirantis Version

Moby

25.0.9

25.0.9m1

Docker CLI

25.0.7

25.0.9m1

containerd

1.7.26

1.7.26m1

runc

1.2.5

1.2.5m1

cri-dockerd

0.3.15

buildx

0.12.1m

0.12.1m1

Fipster (Go runtime)

go1.22.12

go1.22.12m1

buildkit

0.12.5

rootlesskit

1.0.2