Skip to main content

Bitdefender Endpoint Security Tools for Linux

This section contains the release notes for Bitdefender Endpoint Security Tools (BEST) for Linux. For the BEST for Linux user's guide, go to this section.

Version 7.4.0.200181

Release date:

  • Fast ring: 2024.11.25

  • Slow ring: 2024.11.26

New features

Antimalware

  • Linux endpoints now support adding hash values to the Blocklist in the Incidents section. To read more, refer to the Add rules to the Blocklist > Adding hash values to the Blocklist section on the Blocklist page.

    Important

    • This functionality is available only with specific kernels. For more information, refer to Linux kernels supported by Blocklist and Application Blacklisting.

    • This is an Antimalware functionality. The EDR Sensor is not required in the installation package.

    • Any blocking rule applied to Linux containers will be ignored. Applications on the container host can be blocked by hash.

    • Adding application paths and connections to the Blocklist is not currently supported.

  • Linux endpoints now support configuring Application Blacklisting in the Network Protection > Content Control > Application Blacklisting section within the policy settings. To read more, refer to the Application Blacklisting section on the Content Control page.

    Important

    • This functionality is available only with specific kernels. For more information, refer to Linux kernels supported by Blocklist and Application Blacklisting.

    • This is an Antimalware functionality. The Content Control is not required in the installation package.

    • Any application rule applied to Linux containers will be ignored. Applications on the container host can be blocked by path.

    • Scripts can be blocked by path only when they are executed directly, not explicitly loaded by an interpreter. They can start with a shebang or they can be shell scripts without a shebang.

  • Added support for upcoming features available with the next major GravityZone release.

Container Protection

Added support for upcoming features available with the next major GravityZone release.

Improvements

Antimalware

  • Optimized the antimalware scanning mechanism to minimize system boot delays when scheduled scans are missed.

  • All on-demand scan tasks now have the Preserve last access time setting available on Linux endpoints, too. Read more: Malware scan.

Security Container

  • You can now configure an optional group ID (GID) parameter when deploying Bitdefender Security Containers on a Linux container host. This prevents potential issues caused by the default GID 10000 already being used.

  • Added support for the following container platforms:

    • Openshift (4.13 – 4.17.2)

    • RKE2 (2.8)

Product

Added support for the following distributions:

  • Zorin OS

  • SLES 15 SP6

  • Linux Mint Debian Edition 6

Resolved issues

Endpoint Detection and Response

Fixed an issue that caused a size increase of the /opt/bitdefender-security-tools/var/edrsubmitter/ directory up to 4 GB.

Antimalware

  • Resolved an issue causing bduitool get ps to display the status of an unsupported feature.

  • Fixed a bug that caused /bin/bash to be wrongly reported as malware inside containers.

  • Internal bugs have been resolved.

Known issues

Antimalware

  • On the Blocklist page, scripts can be blocked by hash only if they start with a shebang (#!).

  • In the Application Blacklisting policy section, applications can be blocked only with the Block All option selected. Blocking rules for scheduled applications are not saved.

  • On-access exclusions take priority over blocking rules. Any application specified in a blocking rule will not be blocked if:

    • Its location is excluded from on-access scanning as an object of type Folder.

    • It is excluded from on-access scanning as an object of type File.

    • Its extension is excluded from on-access scanning.

    • It is accessed by a process excluded from on-access scanning as an object of type Process.

Version 7.4.0.200180

Release date:

  • Fast ring: 2024.11.18

  • Slow ring: –

New features

Antimalware

  • Linux endpoints now support adding hash values to the Blocklist in the Incidents section. To read more, refer to the Add rules to the Blocklist > Adding hash values to the Blocklist section on the Blocklist page.

    Important

    • This functionality is available only with specific kernels. For more information, refer to Linux kernels supported by Blocklist and Application Blacklisting.

    • This is an Antimalware functionality. The EDR Sensor is not required in the installation package.

    • Any blocking rule applied to Linux containers will be ignored. Applications on the container host can be blocked by hash.

    • Adding application paths and connections to the Blocklist is not currently supported.

  • Linux endpoints now support configuring Application Blacklisting in the Network Protection > Content Control > Application Blacklisting section within the policy settings. To read more, refer to the Application Blacklisting section on the Content Control page.

    Important

    • This functionality is available only with specific kernels. For more information, refer to Linux kernels supported by Blocklist and Application Blacklisting.

    • This is an Antimalware functionality. The Content Control is not required in the installation package.

    • Any application rule applied to Linux containers will be ignored. Applications on the container host can be blocked by path.

    • Scripts can be blocked by path only when they are executed directly, not explicitly loaded by an interpreter. They can start with a shebang or they can be shell scripts without a shebang.

  • Added support for upcoming features available with the next major GravityZone release.

Container Protection

Added support for upcoming features available with the next major GravityZone release.

Improvements

Antimalware

  • Optimized the antimalware scanning mechanism to minimize system boot delays when scheduled scans are missed.

  • All on-demand scan tasks now have the Preserve last access time setting available on Linux endpoints, too. Read more: Malware scan.

Security Container

  • You can now configure an optional group ID (GID) parameter when deploying Bitdefender Security Containers on a Linux container host. This prevents potential issues caused by the default GID 10000 already being used.

  • Added support for the following container platforms:

    • Openshift (4.13 – 4.17.2)

    • RKE2 (2.8)

Product

Added support for the following distributions:

  • Zorin OS

  • SLES 15 SP6

  • Linux Mint Debian Edition 6

Resolved issues

Endpoint Detection and Response

Fixed an issue that caused a size increase of the /opt/bitdefender-security-tools/var/edrsubmitter/ directory up to 4 GB.

Antimalware

  • Resolved an issue causing bduitool get ps to display the status of an unsupported feature.

  • Fixed a bug that caused /bin/bash to be wrongly reported as malware inside containers.

Known issues

Antimalware

  • On the Blocklist page, scripts can be blocked by hash only if they start with a shebang (#!).

  • In the Application Blacklisting policy section, applications can be blocked only with the Block All option selected. Blocking rules for scheduled applications are not saved.

  • On-access exclusions take priority over blocking rules. Any application specified in a blocking rule will not be blocked if:

    • Its location is excluded from on-access scanning as an object of type Folder.

    • It is excluded from on-access scanning as an object of type File.

    • Its extension is excluded from on-access scanning.

    • It is accessed by a process excluded from on-access scanning as an object of type Process.

Version 7.3.0.200172

Release date:

  • Fast ring: 2024.10.31

  • Slow ring: 2024.11.04

Resolved issues

Endpoint Detection and Response

Fixed an issue that caused the /opt/bitdefender-security-tools/var/edrsubmitter/ directory to increase to 4 GB.

Version 7.2.1.200170

Release date:

  • Fast ring: 2024.10.03

  • Slow ring: 2024.10.07

Resolved issues

Internal bugs have been resolved.

Version 7.2.1.200168

Release date:

  • Fast ring: 2024.09.18

  • Slow ring: 2024.09.19

Resolved issues

Security Telemetry

Resolved an issue where BEST would repeatedly crash if the SIEM server URL, configured in General > Security Telemetry > SIEM Connection Settings within the policy settings, was invalid or incorrectly formatted.

Update server

Fixed an issue where changing the URLs in Relay > Update > Update Locations within the policy settings had no effect.

Version 7.2.1.200164

Release date:

  • Fast ring: 2024.09.04

  • Slow ring: 2024.09.09

New Features

Security Telemetry

When MDR is enabled, you can now send telemetry data simultaneously to the MDR team and to your own SIEM server configured in the General > Security Telemetry policy section.

Product

Added support for upcoming features available with the next major GravityZone release.

Resolved issues

Product

VirtualBox no longer crashes due to uprobes when you try to run a virtual machine on an endpoint with BEST installed.

Tasks

Resolved an issue where BEST failed to consider whether the Reconfigure task used the proxy setting from the update location.

Version 7.2.0.200144

Release date:

  • Fast ring: 2024.07.29

  • Slow ring: 2024.08.05

New Features

Endpoint Detection and Response

Added support for upcoming features available with the next major GravityZone release.

Improvements

Endpoint Risk Analytics

Any Endpoint Risk Analytics scan that fails, is interrupted, or is incomplete is now automatically retried three times.

Resolved issues

Product

  • Added kprobes support for kernel 6.9.3-76060903-generic.

  • The GDB debug tool no longer gives SIGTRAP error when Bitdefender Endpoint Security Tools for Linux is installed on SUSE Linux Enterprise 15.0, SUSE Linux Enterprise 15.1, or openSUSE Leap 15.0 systems.

Version 7.1.1.200141

Release date:

  • Fast ring: 2024.06.10

  • Slow ring: 2024.06.11

Resolved issues

  • Security fixes

Version 7.1.1.200135

Release date:

  • Fast ring: 2024.05.30

  • Slow ring: 2024.06.04

New Features

Advanced Threat Control

Bitdefender Advanced Threat Control is now available for Linux in report-only mode. This means that whether the preferred security level is Aggressive, Normal, or Permissive, the module takes no action except to report the infected applications detected by Bitdefender.

It can be installed at the creation of a new installation package, by selecting the Advanced Threat Control option. Learn more.

Resolved issues

Product

  • Added On-Access compatibility for kernels 2.6.32-754.50.1.el6.x86_64.rpm and 2.6.32-754.53.1.el6.x86_64.rpm.

  • Cloud Services are now accessible when the DNS server is not configured and the relay is used as a proxy.

Version 7.1.0.200110

Release date:

  • Fast ring: 2024.04.16

  • Slow ring: 2024.04.23

New Features

Security Telemetry

You can now forward security telemetry events from Linux endpoints to a syslog server in JSON format.

Tip

You can enable this feature on Linux endpoints from the General > Security Telemetry > SIEM Connection Settings section of the policies applied to them. Learn more.

Improvements

Product

  • Reduced the Bitdefender Endpoint Security Tools installation time for virtual machines that are hosted on premises.

  • Optimized the hard disk space occupied by the agent. Unnecessary files are automatically deleted after installation.

Antimalware

  • On-Demand scans now consume less RAM and swap space.

  • Added support for upcoming features available with the next major GravityZone release.

Patch Management

Updated libicu to the latest versions corresponding to the supported distributions by the Patch Management feature.

Warning

For SLES 15 operating systems, Patch Management now supports only SLES 15 SP5 or higher.

Resolved issues

Antimalware

Resolved the timeout error at the bduitool get scanlog command. Now the command completes in less than 60 seconds. In lack of previous scan tasks, the command will finish without any message.

Endpoint Detection and Response

The Endpoint Detection and Response module no longer causes high CPU usage due to processing unnecessary events. For these events, we have added exclusions.

Version 7.0.5.200090

Release date:

  • Fast ring: 2024.03.07

  • Slow ring: 2024.03.11

Important

This update includes all improvements and fixes from version 7.0.5.200087, released on fast ring.

Resolved issues

  • Security fixes

Version 7.0.5.200087

Release date:

  • Fast ring: 2024.02.29

  • Slow ring: -

Resolved issues

  • Resolved an issue causing increased CPU usage on Red Hat Enterprise endpoints running with the EDR Sensor module installed.

  • Security fixes

Version 7.0.5.200075

Release date:

  • Fast ring: 2024.02.06

  • Slow ring: 2024.02.13

Improvements

  • Added support for the Pop!OS operating system with kernel version 6.6.6-76060606-generic.

Resolved issues

  • You can now properly install and use the Patch Management module on endpoints with SUSE Linux Enterprise Server 15 SP5.

  • Malware detections on virtual machines are now properly transmitted and displayed under Incidents, Threats Xplorer, Executive summary and the Security audit report. The issue sometimes occurred when Container Protection was not installed on the machine.

  • Resolved an issue causing Malware Status reports to be displayed under Scan Logs when viewing endpoint details from the Network page.

  • Fixed an issue causing scans to add folder and subfolder paths to scan lists despite being excluded in the policy applied to the endpoint. This was causing increased RAM usage.

  • Security fixes

Version 7.0.5.200049

Release date:

  • Fast ring: 2023.12.11

  • Slow ring: 2023.12.12

Important

This update includes all improvements and fixes from version 7.0.5.200046 released on fast ring.

Improvements

  • Stability fixes.

Version 7.0.5.200048

Release date:

  • Fast ring: 2023.12.06

  • Slow ring: -

Improvements

  • Security and stability fixes.

Version 7.0.5.200046

Release date:

  • Fast ring: 2023.12.04

  • Slow ring: -

Improvements

  • Incidents are now created when Integrity Monitoring rules with the critical severity level are triggered.

  • BEST for Linux is now limited at using 50% of an endpoint's CPU usage when performing On-Demand scans with low priority.

  • The Paused/Suspended, and Stopped statuses are now available for container endpoints when displayed in the the GravityZone console.

  • BEST for Linux is now compatible with the following distributions:

    • Fedora 39 x64

    • OpenSUSE Leap 15.5 x64

  • You can now use ** wild card exclusions for On-Access scans. The feature works for both files and folders.

Resolved issues

  • BEST for Linux now properly identifies Amazon Web Service EC2 with IMDSV2 when deployed with the automatic scan mode.

  • On-Access scans that run on container hosts with BEST for Linux deployed with Container protection now exclude folders where container engines unpack image layers and mount overlay file systems.

  • Fixed an issue where Docker container namespaces were still protected by BEST for Linux after the container was removed.

  • Incidents now show the correct action taken for events where items were quarantined as a result of a malware detection.

Version 7.0.3.2322

Release date:

  • Fast ring: 2023.11.16

  • Slow ring: 2023.11.16

Resolved Issues

  • Resolved an issue causing some security updates to fail when performed through a Relay.

Version 7.0.3.2319

Release date:

  • Fast ring: 2023.11.13

  • Slow ring: 2023.11.14

Resolved Issues

  • Resolved an issue causing some log files to be mistakenly generated in the "/" directory during security updates.

  • Security fixes

Version 7.0.3.2312

Release date:

  • Fast ring: 2023.11.13

  • Slow ring: -

Resolved Issues

  • Security fixes

Version 7.0.3.2271

Release date:

  • Fast ring: 2023.09.04

  • Slow ring: 2023.09.07

New features

  • Added support for upcoming features available with the next major GravityZone release.

Resolved issues

  • The Network Attack Defense module no longer blocks SSH connections with other endpoints.

Known issues

  • Custom detection rules that have a Parent Name matching criteria with a wildcard currently do not work.

  • The Antimalware feature does not currently work on CentOS 7 operating systems using ARM architectures (aarch64).

Version 7.0.3.2248

Release date:

  • Fast ring: 2023.08.17

  • Slow ring: -

New features

  • Added support for upcoming features available with the next major GravityZone release.

Resolved issues

  • The Network Attack Defense module no longer blocks SSH connections with other endpoints.

Known issues

  • Custom detection rules that have a Parent Name matching criteria with a wildcard currently do not work.

  • The Antimalware feature does not currently work on CentOS 7 operating systems using ARM architectures (aarch64).

Version 7.0.3.2239

Release date:

  • Fast ring: 2023.07.25

  • Slow ring: 2023.07.26

Improvements

  • Security fixes

Version 7.0.3.2225

Release date:

  • Fast ring: 2023.07.13

  • Slow ring: 2023.07.24

New features

  • You can now upload and download files when using the Remote Shell feature on Linux endpoints. Learn more

  • You can now cancel any ongoing or pending file transfers resulted from the use of the Remote Shell feature.

  • The Delete all button is now available: all the entries will be removed from the Investigation grid and all pending or ongoing downloads will be canceled.

Improvements

  • BEST for Linux v7 is now compatible with the following distributions:

    • Kylin v10 x64 (RPM-based)

    • SLED 15 SP4 x64

    • Ubuntu 23.04 x64

    • Ubuntu 22.10 x64

    • Debian 12 x64

    • Fedora 38 x64

  • BEST for Linux us now compatible with ARM architecture (aarch64).

  • The curl table used by the Live Search feature is now disabled on endpoints with BEST for Linux installed. This was done to protect against exploits involving lateral movement attacks.

  • Added the efivar library in BEST for Linux packages, covered under GNU Lesser General Public License, version 2.1.

Resolved issues

  • Removed support for several DazukoFS module kernel archives. The following archives are still supported:

    • 2.6.32-754.35.1.el6.x86_64

    • 2.6.32-754.35.1.el6.centos.plus.x86_64

    • 2.6.32-754.35.1.el6.i686

    • 2.6.32-754.35.1.el6.centos.plus.i686

  • Updated the OpenSSL library to version 1.1.1u.

  • Updated libssh library to version 0.10.5.

  • Endpoints using the Network Attack Defense feature now use the netfilter conntrack helper component to avoid routing all ports for FTP connections.

  • Network Attack Defense no longer blocks access to the Oracle MySQL Workbench 8.0.29 database when deployed with BEST for Linux.

  • Resolved an issue causing File, Folder or Process scanning exclusions to not include subfolders when a / is added at the end of the folder path.

  • Launching BEST for Linux now properly cleans Bitdefender AuditD rules at startup.

  • Downloading an installation kit on a relay now properly removes older kits from the endpoint. An issue was causing the maximum number of kits that are allowed on a relay endpoint to be exceeded by 1.

  • Fixed an issue causing endpoints with BEST for Linux to display the Connection to the Cloud services cannot be established notification, despite it being disabled from the policy applied on the endpoint. The setting can be found under General > Notifications > Endpoint Issues Visibility > Modular Settings > Cloud Services notifications.

  • Endpoints with BEST for Linux installed are no longer connecting directly to the GravityZone cloud services despite them being configured to connect through a proxy.

  • On-demand scans are no longer interrupted when performed on archives larger than 4 GB.

  • Fixed an issue which could lead to potential deadlocks within the EDR module.

  • BEST for Linux now stops querying update servers once a connection is established.

  • Fixed an issue causing BEST for Linux updates to fail, returning error 403.

  • Failed product updates now properly fall back to the next available update server.

Removed features

  • Removed support for Patch Management for the following distributions:

    • RedHat 6

    • CentOS 6

Known issues

  • Decrypting documents downloaded from Remote shell sessions returns an error (decryption forced to fail!), despite the decryption being successful.

  • BEST for Linux sometimes fails to start after the endpoint where it is deployed is upgraded from init.d to systemd. To resolve this issue refer to this article.

  • Remote shell sessions are currently not displaying certain special characters.

  • Moving to the /opt/bitdefender-security-tools/ directory during a remote shell session incorrectly returns error 123 instead of error 313.

  • Trying to use a read-only network mount as an upload path during a remote shell session incorrectly returns error 0 instead of error 5 - access denied.

Version 7.0.3.2193

Release date:

  • Fast ring: 2023.05.15

  • Slow ring: 2023.05.17

Resolved issues

  • BEST updates no longer refresh update repositories on SLES operating systems.

  • Fixed an issue causing BEST to mount NFS shares as a result of on-demand scans.

  • Updating BEST no longer restores NAD module script execution rights to default.

Improvements

  • On-demand scans that run with low priority now only use half of available endpoint resources.

Version 7.0.3.2177

Release date:

  • Fast ring: 2023.04.11

  • Slow ring: 2023.04.19

Improvements

  • BEST for Linux is now compatible with the PopOS and Amazon Linux 2023 distributions.

  • KProbes now support security content update rings.

  • You can now use On-Access scanning for files in the root (/) directory on containers protected by BEST.

  • The Support Tool now gathers additional logs.

  • You can now use the Support Tool with Bitdefender Security for Containers.

  • Added support for upcoming features available with the next major GravityZone release.

  • Security containers are now deployed in a dedicated namespace on Kubernetes: bitdefender-security-container.

  • Security containers now use a dedicated Kubernetes service account: bitdefender-security-container.

Removed features

  • All RHEL and RHEL derivatives (for example, CentOS and Oracle) prior 6.10 are no longer supported.

Limitations

  • Deploying Security Containers on OpenShift 4.12 and later environments using the Helm package manager is currently unsupported.

Resolved issues

  • Fixed multiple compatibility issues between BEST for Linux and NFS mounts.

  • Security and stability fixes.

Version 7.0.3.2120

Release date:

  • Fast ring: 2023.01.31

  • Slow ring: 2023.02.07

Resolved issues

  • Endpoints with the Network Attack Defense module deployed are no longer experiencing connectivity issues.

  • Reconfigure client tasks configured with the Match List option no longer fail when the endpoints are communicating through a Relay.

  • Fixed an issue causing the Antimalware module to sometimes crash when performing On-access scan tasks.

  • Deploying BEST for Linux on endpoints not using the default package manager of their operating system no longer fails.

Version 7.0.3.2115

Release date:

  • Fast ring: 2022.12.12

  • Slow ring: 2022.12.15

New features

  • Outbound monitoring is now available for Network Attack Defense on Linux endpoints.

Improvements

  • Added support for Oracle Linux 8 and Oracle Linux 9 5.15 kernel versions.

  • DNF is now the first choice package manager for YUM based operating systems when installing and updating BEST for Linux.

Resolved issues

  • Reconfigure Client tasks with Match List option selected now properly execute for endpoints with a Linux Relay set as an update location. The tasks used to fail, returning a no suitable update server found error.

  • The EDR module no longer causes increased CPU usage when enabled.

  • Fixed an issue causing endpoints with BEST for Linux installed not to appear in the Active Directory tree.

Version 7.0.3.2106

Release date:

  • Fast ring: 2022.11.21

  • Slow ring: 2022.11.21

Improvements

  • Security fixes

Version 7.0.3.2104

Release date:

  • Fast ring: 2022.11.16

  • Slow ring: 2022.11.17

Improvements

  • Added support for upcoming features available with the next major GravityZone release.

  • KProbes are now available for Linux kernel 6.0.

  • Security fixes.

Version 7.0.3.2085

Release date:

  • Fast ring: 2022.10.13

  • Slow ring: 2022.10.17

Improvements

  • On demand scans are now available for autofs network shares.

  • Network Attack Defense now runs as a separate process. This will considerably improve stability.

  • The process exclusions from your GravityZone policies now apply to EDR events from endpoints with BEST for Linux installed.

  • You can now define assignment rules based on endpoint hostname.

  • Live Search now returns a limited amount of information to GravityZone from endpoints with BEST for Linux deployed. The total number of rows generated by the search is included in the response.

Resolved issues

  • Fixed an issue causing Container Protection to only scan the first two levels of a file path.

  • Product updates on SLES 12.5 are no longer failing due to zypper license agreement.

  • Product updates now properly ignore global apt proxy settings.

Version 7.0.3.2061

Release date:

  • Fast ring: 2022.09.12

  • Slow ring: 2022.09.19

Improvements

  • Added support for additional Fedora kernels. Learn more

Resolved issues

  • Security fixes

Version 7.0.3.2050

Release date:

  • Fast ring: 2022.08.16

  • Slow ring: 2022.08.16

Resolved issues

  • The files used by BEST for Linux when EDR is enabled through AuditD now revert to default when no longer needed. This occurs when EDR is disabled or when kprobes are used instead of AuditD.

Version 7.0.3.2038

Release date:

  • Fast ring: 2022.08.03

  • Slow ring: 2022.08.03

Resolved issues

  • Fixed an issue causing security updates to fail and increase CPU usage in certain situations.

Version 7.0.3.2034

Release date:

  • Fast ring: 2022:08.01

  • Slow ring: 2022:08.02

Important

This update includes all improvements and fixes from version 7.0.3.2030 released on fast ring.

Resolved issues

  • Security fixes

Version 7.0.3.2030

Release date:

  • Fast ring: 2022.07.28

  • Slow ring:

New features

  • The Network Attack Defense module is now available for Linux. Learn more

  • EDR Custom rules are now applicable to endpoints with BEST for Linux v7.

Improvements

  • BEST for Linux v7 is now compatible with the following distributions:

    • CBL-Mariner 2

    • Ubuntu 22.04

    • Red Hat Enterprise Linux 9

    • AlmaLinux 9

    • Fedora 36

  • Added support for the Amazon Linux 2 5.10.x and 5.15.x kernel versions.

  • Antimalware engines are no longer loaded when on-access scanning is disabled. This feature does not apply to endpoints where the Container Protection module is installed.

Resolved issues

  • The Security Telemetry feature now properly displays the connection status to the telemetry servers.

  • BEST for Linux no longer causes high CPU usage when EDR is enabled.

  • Fixed issue causing servers with BEST for Linux to freeze. This was caused by resetting the firewall while using central scan with a hybrid fallback.

  • Using BEST for Linux with AuditD on systems running on Red Hat Enterprise Linux Server 6.7 no longer causes high resource usage.

  • Closing BEST for Linux v7 now properly terminates the active instance of the program.

  • Fixed issue causing BEST for Linux v7 to gradually increase RAM usage over time.

Known issues

  • Starting or stopping Network Attack Defense will reset all active connection done through ports 21 and 22.

Version 7.0.3.2004

Release date:

  • Fast ring: 2022.05.12

  • Slow ring: 2022.05.12

Resolved issues

  • On-Demand scanning tasks with low priority no longer cause high CPU usage.

  • Assignment rules based on location now properly apply policies to the target IP addresses.

  • Quarantined items are now automatically removed as per the policy configuration.

Version 7.0.3.1999

Release date:

  • Fast ring: 2022.05.09

  • Slow ring: 2022.05.10

Improvements

  • The Send feedback regarding security agents’ health and Use Bitdefender Global Protective Network to enhance protection policy options now also apply to endpoints with BEST for Linux deployed. You can find the options under General > Settings > Options when editing a policy.

  • EDR Custom Rules are now applicable on endpoints where BEST for Linux is deployed.

Resolved issues

  • Installing BEST for Linux v7 on an endpoint no longer overwrites the locally configured OSQuery service.

  • Deploying BEST for Linux on an Amazon Linux Docker environment no longer causes an increased resource usage.

  • Fixed an issue that was affecting the communication between BEST for Linux and GravityZone due to an improper integration with Active Directory.

  • Deploying BEST for Linux on an Red Hat Enterprise environment no longer causes increase CPU usage.

Version 7.0.3.1986

Release date:

  • Fast ring: 2022.04.04

  • Slow ring: 2022.04.06

Important

This update includes all improvements and fixes from versions 7.0.3.1982 and 7.0.3.1984 released on fast ring.

Resolved issues

  • Resolved a critical issue occurred after the last product update.

Version 7.0.3.1984

Release date:

  • Fast ring: 2022.03.31

  • Slow ring: -

Resolved issues

  • Fixed a configuration problem for BEST Relay.

Version 7.0.3.1982

Release date:

  • Fast ring: 2022.03.31

  • Slow ring: -

New features

  • Patch Management now supports Smart Scan on Linux.

  • Added support for Investigation packages for both BEST for Linux v7 and SDK.

Improvements

  • BEST for Linux is now compatible with Linux Mint and Miracle Linux.

  • Deploying or updating BEST for Linux with EDR using Linux AuditD now automatically updates configuration files.

  • Added support for the Shut down computer when scan is finished option scan option.

  • Memory usage has been optimized when using system's AuditD.

  • EDR events generation has been optimized.

  • Added detection for the exploitation of the CVE-2022-0847 vulnerability.

  • Information on errors related to Patch Management is now available here.

  • Improved product description in Docker Hub.

Resolved issues

  • BEST for Linux now detects Linux AD integrations.

  • Attempting to enable SSL on certain server types no longer causes an indefinite retry loop. This would also cause log files to be flooded with error messages.

  • Fixed issue causing high CPU usage on systems with BEST for Linux using AuditD.

  • Java applications no longer slow down after installing BEST for Linux on endpoints running on the RHEL 7 and RHEL 8 operating systems.

  • Using a script to write files in a high number simultaneously no longer causes high CPU utilization.

  • Resolved issue causing high CPU utilization when using EDR.

  • Custom Scan tasks no longer scan shared file paths when the Scan network share option is not selected.

  • Fixed issue causing On-Access scans to miss threats during performance tests.

  • CIFS and NFS protocols are no longer restricted for systems that use the Fanotify notification system.

  • Fixed issue causing On-Demand scan task reports to fail to register in logs.

  • On-Demand scan logs from endpoints with BEST for Linux v7 now appear properly in Control Center.

Known issues

  • On-Access scanning does not detect threats in network paths mounted using Amazon EFS.

Version 7.0.3.1956

Release date:

  • Fast ring: 2022.03.10

  • Slow ring: 2022.03.10

Improvements

  • Reduced memory consumption in certain scenarios where EDR is active.

Version 7.0.3.1948

Release date:

  • Fast ring: 2022.02.17

  • Slow ring: 2022.02.21

Improvements

  • Optimized the error logging and update mechanisms.

Version 7.0.3.1942

Release date:

  • Fast ring: 2022.02.07

  • Slow ring: 2022.02.07

Resolved issues

  • Fixed an issue causing slow product initialization.

Version 7.0.3.1941

Release date:

  • Fast ring: 2022.02.03

Resolved issues

  • Linux machines integrated into Active Directory are now being properly detected and appear under the GravityZone console.

  • Applying policies no longer generates unnecessary EDR related events causing high CPU usage. This was occurring due to EDR events remaining active while the EDR Sensor was disabled and Advanced Anti-Exploit remained enabled.

  • The bdsecd process used for debug logging no longer causes high CPU usage

Version 7.0.3.1927

Release date: 2021.12.24

Resolved issues

  • All events are now being sent to Splunk servers.

Known issues

  • Event submissions to Splunk servers currently fail without a fully signed SSL certificate.

Version 7.0.3.1922

Release date: 2021.12.16

New features

  • Patch Management is now available for BEST for Linux. You can find a list of compatible operating systems here.

Improvements

  • You can now schedule recurring product and security content updates to run on endpoints. You can set the task to run on a specific day of the week or after a certain time has passed since the last occurrence.

  • A notification is now sent when a system restart is required. You can choose to immediately restart or postpone the process.

  • You can now enable an automatic shutdown or system restart based on specific scenarios such as product update or disinfection.

  • The Restart machine task is now available for Linux endpoints.

  • Antimalware events history is now available locally.

Resolved issues

  • Updating BEST for Linux now properly deletes all previous installation packages present on the endpoint.

  • Resolved multiple issues causing the security agent to crash or freeze.

  • All scan tasks ran through the Bitdefender User Interface Tool (bduitool) now receive unique IDs.

Version 7.0.3.1903

Release date: 2021.12.01

Improvements

  • Product update mechanism via our agent installer has been enhanced.

Version 7.0.3.1899

Release date:

  • Fast ring: 2021.11.23

  • Slow ring: 2021.11.25

Improvements

Product

  • You can now apply policies based on location assignment rules.

  • BEST for Linux v7 is now compatible with the following Linux distributions:

    • Rocky Linux 8.x

    • Pardus 21.0x

    • Alma Linux 8.x

    • Ubuntu 21.04 & 21.10

    • Cloud Linux OS

  • BEST for Linux v7 is now compatible with 32-bit operating systems on the following distributions:

    • CentOS 6    

    • CentOS 7

    • CentOS 10

    • Debian 11

    • Debian 9

    • Red Hat Enterprise Linux 6

    • Ubuntu 14

    • Ubuntu 16

  • BEST for Linux v7 now supports DazukoFS for kernel versions 2.6.32.

Note

As a result of these improvements, feature parity between versions 6 and 7 has been achieved.

Resolved issues

Product

  • BEST for Linux v7 installer no longer incorrectly reports that there is not enough space on disk when the /opt/bitdefender-security-tools file exists.

  • Starting an installation of BEST for Linux v7 on an endpoint with an older version of v7 installed no longer returns "The product is already installed".

  • Fixed the issue causing increased RAM usage on Ubuntu machines.

  • Product updates no longer fail when the Relay URL address has a slash (/) at the end.

  • Running the deliverall command no longer archives the dnf folder on machines where BEST for Linux v7 has been updated from an older version.

  • Product updates no longer fail on SUSE operating systems.

  • Updating BEST for Linux v6 to v7 now properly creates the /usr/bin/bd symlink file.

Support Tool

  • Troubleshooting Debug session tasks no longer remain in an In progress state.

Advanced Anti-Exploit

  • Alerts are no longer incorrectly triggered for pkexec and policykit processes.

Version 7.0.3.1869

Release date: 2021.11.16

Resolved issues

Product

  • Security fixes

Version 7.0.3.1868

Release date: 2021.11.03

Resolved issues

Product

  • Background periodic clean-up of temporary support files no longer causes Bitdefender systems to crash.

Version 7.0.3.1862

Release date: 2021.10.28

Resolved issues

Product

  • Security content updates no longer cause scan servers to reload.

  • Repeated deployments via Relay on the same endpoint no longer apply the same BEST version. This would occur regardless of the specified deployment settings.

  • Resolved an issue causing the Quarantine module to fail clearing file descriptors during scans, resulting in higher resource usage.

Improvements

On-Access

  • Files previously confirmed as clean and unmodified are no longer scanned when accessed.

Version 7.0.3.1850

Release date:

  • Fast ring: 2021.10.21

  • Slow ring: 2021.10.25

Improvements

Product

  • Support Tool is now available for BEST for Linux v7.

Container Protection

  • On-Access protection is now available for Security Container Hosts.

  • Container Protection is now compatible with OpenShift CRI-O Container Engine.

Resolved issues

Product

  • Installing BEST for Linux on an VM with an RPM-based OS after clearing the yum cache no longer fails when no internet access is available.

Known issues

Product

  • During scans, the Quarantine module does not clear file descriptors, resulting in higher resource usage.

Version 7.0.1.1774

Release date:

  • Fast ring: 2021.10.04

  • Slow ring: 2021.10.05

Resolved issues

Product

  • (bduitool) is now available for BEST for Linux v7.

  • Bitdefender user no longer appears in GNOME GUI environments.

  • BEST for Linux v7 no longer takes ownership of certain APT files, making software updates to fail.

Known issues

On-demand

  • Changing the system time on an endpoint that has scheduled custom scans causes Bitdefender product to crash.

Version 7.0.1.1762

Release date: 2021.09.29

Resolved issues

Product

  • Kprobes is no longer failing to load after security content updates.

  • Fixed issue causing update tasks run on machines with BEST for Linux v7.0.1.1626 installed to fail despite the console showing the update as successful.

Version 7.0.1.1754

Release date: 2021.09.23

Improvements

Product

  • Logs folder location has been changed from /tmp to /opt/bitdefender-security-tools/var/tmp.

  • Network Isolation tasks now work on endpoints which have a proxy configured.

  • Support tool is now available for BEST for Linux v7. It is currently available only from the command line interface.

EDR

  • The performance of the incidents sensor has been increased by as much as 30% in certain scenarios.

  • Extended the EDR support to Amazon Bottlerocket.

Resolved issues

Product

  • Policies now correctly apply communication settings to endpoints that have been upgraded from BEST for Linux v6 to v7.

  • GravityZone now properly detecting new deployments of Patch Management.

  • Running a Reconfigure Client task now correctly checks available disk space before installing a Relay role. The installation will only begin if sufficient disk space is available.

  • Uninstalling BEST for Linux v7 from virtual machines no longer results in a crash in certain situations.

  • BEST for Linux v7 now properly updating on all SLES machines.

  • Running BEST for Linux installation packages downloaded from a custom host no longer fail.

  • BEST for Linux v7 now compatible with machines working with FIPS protocol.

  • Fixed issue causing policies not to apply correctly when done through a Relay.

  • Security fixes.

Advanced Anti-Exploit

  • Custom scan exclusions now properly loading.

  • On-Access scans no longer scan removed scan paths specified in your policy settings.

  • Added exceptions for alerts related to package managers (apt, yum, dnf).

  • Techniques are now properly displayed for corresponding generated events.

Container Protection

  • Container logs now properly record Security Container updates.

  • Restoring a quarantined file to a container now correctly places the file back on the container instead of the host VM.

  • Security Containers now work properly with Bottlerocket OS.

Version 7.0.1.1725

Release date: 2021.09.09

Resolved issues

Antimalware

  • Security content updates no longer cause On-Demand scans to return no results.

Version 7.0.1.1713

Release date: 2021.09.07

Improvements

  • Network Isolation for EDR is now available.

Resolved issues

Product

  • Upgrading BEST for Linux from v6 to v7 no longer causes issue where both BEST versions run on the same endpoint.

  • Upgrading BEST for Linux from v6 to v7 no longer causes On-Demand scans to return no results.

Relay role

  • The Relay role is now supported again.

Known issues

  • Network Isolation disconnects endpoints from the network, causing a loss of connectivity with GravityZone. This issue only occurs for endpoints that use policies with proxy configurations.

    Note

    To change the proxy settings, go to the General > Communication policy section and choose another option for Communications between Endpoints and Relays / GravityZone.

Version 7.0.1.1626

Release date: 2021.08.12

Resolved issues

Product

  • Policies applied to Security Containers now function independently of policies applied to the host.

  • Enabling On-Access on policies that have already been applied no longer fails to activate the service.

  • HTTPS protocol updates no longer fail on certain operating systems.

  • Running an Update client task for both product and security content no longer fails to perform the security content update.

  • Scan reports now show the correct number of scanned files.

Version 7.0.1.1582

Release date: 2021.08.12

Improvements

Container Protection

  • Podman inventory support now available.

Resolved issues

Product

  • Update tasks now show correct status after failing.

  • Using On-Access scanning on a Ubuntu container no longer causes Bitdefender services to sometimes crash.

  • Issues no longer appear when trying to remove malware from certain archives.

Container Protection

  • Container runtime now registers properly in all environments.

  • When applying policies to containers, configured actions now apply correctly when malware is detected, including on older kernel versions.

  • Kprobes no longer being reloaded when no new updates are available.

Version 7.0.1.1556

Release date: 2021.08.06

Resolved issues

Product

  • Product updates no longer failing when no update locations are added to the policy you are using.

Version 7.0.1.1551

Release date: 2021.08.05

Resolved issues

Product

  • Product now correctly showing status for disabled modules.

  • Performing a scan task during a security content update no longer causes Bitdefender services to sometimes crash.

  • Using a proxy server no longer prevents EDR incidents from being generated.

Version 7.0.1.1520

Release date: 2021.07.29

BEST for Linux v7 is now available with a new set of features and benefits, including:

Features

  • Container Protection – protects both the container host and its running containers.

  • A new anti-exploit module.

Benefits and improvements

  • A new architecture, created using Kprobes instead of kernel modules, which eliminates the common delays or the need to sacrifice security when upgrading.

  • Greatly expanded platform compatibility to all Enterprise Linux distributions and cloud native Linux distributions.

Known issues

  • Policy per location not supported.

  • Bduitool not supported.

  • Relay role not supported.

  • Remote troubleshooting not supported.

  • Has issues status not being removed properly from endpoints once the issue has been resolved.

  • SELinux not supported.

  • EDR Isolate action not supported.

  • Shut down computer when scan is finished option not functioning properly after scan is performed. Endpoints are not being shut down.

  • Restart computer task with Restart now option enabled not functioning properly. Virtual machines and computers are not being restarted.

  • Files in mounted network directories not being scanned through On-Access scanning.

  • Machines with 32-bit OS not supported.

  • Delay in security content update status change after security update.

  • On-Access scanning ignoring file size limitation. All file sizes are scanned.