diff --git a/.internal-ci/docker/Dockerfile.full-service b/.internal-ci/docker/Dockerfile.full-service
index 1f06a3f8df..90649d5076 100644
--- a/.internal-ci/docker/Dockerfile.full-service
+++ b/.internal-ci/docker/Dockerfile.full-service
@@ -5,7 +5,7 @@
 #
 # assume we have pre-built binary
 
-FROM ubuntu:focal-20230308
+FROM ubuntu:focal-20231211
 
 RUN  addgroup --system --gid 1000 app \
   && adduser --system --ingroup app --uid 1000 app \
diff --git a/.internal-ci/docker/Dockerfile.full-service-with-build b/.internal-ci/docker/Dockerfile.full-service-with-build
index 0b70c7b79e..68c7c2a2de 100644
--- a/.internal-ci/docker/Dockerfile.full-service-with-build
+++ b/.internal-ci/docker/Dockerfile.full-service-with-build
@@ -71,7 +71,7 @@ RUN cp /app/target/release/generate-rsa-keypair /usr/local/bin/
 
 # This is the runtime container.
 # Adding/updating OS will not affect the ability to verify the build environment.
-FROM ubuntu:focal-20221019
+FROM ubuntu:focal-20231211
 
 RUN  addgroup --system --gid 1000 app \
   && adduser --system --ingroup app --uid 1000 app \