Bitdefender Endpoint Security Tools for Linux
This section contains the release notes for Bitdefender Endpoint Security Tools (BEST) for Linux. For the BEST for Linux user's guide, go to this section.
Version 7.4.0.200181
Release date:
Fast ring: 2024.11.25
Slow ring: 2024.11.26
New features
Antimalware
Linux endpoints now support adding hash values to the Blocklist in the Incidents section. To read more, refer to the Add rules to the Blocklist > Adding hash values to the Blocklist section on the Blocklist page.
Important
This functionality is available only with specific kernels. For more information, refer to Linux kernels supported by Blocklist and Application Blacklisting.
This is an Antimalware functionality. The EDR Sensor is not required in the installation package.
Any blocking rule applied to Linux containers will be ignored. Applications on the container host can be blocked by hash.
Adding application paths and connections to the Blocklist is not currently supported.
Linux endpoints now support configuring Application Blacklisting in the Network Protection > Content Control > Application Blacklisting section within the policy settings. To read more, refer to the Application Blacklisting section on the Content Control page.
Important
This functionality is available only with specific kernels. For more information, refer to Linux kernels supported by Blocklist and Application Blacklisting.
This is an Antimalware functionality. The Content Control is not required in the installation package.
Any application rule applied to Linux containers will be ignored. Applications on the container host can be blocked by path.
Scripts can be blocked by path only when they are executed directly, not explicitly loaded by an interpreter. They can start with a shebang or they can be shell scripts without a shebang.
Added support for upcoming features available with the next major GravityZone release.
Container Protection
Added support for upcoming features available with the next major GravityZone release.
Improvements
Antimalware
Optimized the antimalware scanning mechanism to minimize system boot delays when scheduled scans are missed.
All on-demand scan tasks now have the Preserve last access time setting available on Linux endpoints, too. Read more: Malware scan.
Security Container
You can now configure an optional group ID (
GID
) parameter when deploying Bitdefender Security Containers on a Linux container host. This prevents potential issues caused by the default GID 10000 already being used.Added support for the following container platforms:
Openshift (4.13 – 4.17.2)
RKE2 (2.8)
Product
Added support for the following distributions:
Zorin OS
SLES 15 SP6
Linux Mint Debian Edition 6
Resolved issues
Endpoint Detection and Response
Fixed an issue that caused a size increase of the /opt/bitdefender-security-tools/var/edrsubmitter/
directory up to 4 GB.
Antimalware
Resolved an issue causing
bduitool get ps
to display the status of an unsupported feature.Fixed a bug that caused
/bin/bash
to be wrongly reported as malware inside containers.Internal bugs have been resolved.
Known issues
Antimalware
On the Blocklist page, scripts can be blocked by hash only if they start with a shebang (
#!
).In the Application Blacklisting policy section, applications can be blocked only with the Block All option selected. Blocking rules for scheduled applications are not saved.
On-access exclusions take priority over blocking rules. Any application specified in a blocking rule will not be blocked if:
Its location is excluded from on-access scanning as an object of type Folder.
It is excluded from on-access scanning as an object of type File.
Its extension is excluded from on-access scanning.
It is accessed by a process excluded from on-access scanning as an object of type Process.
Version 7.4.0.200180
Release date:
Fast ring: 2024.11.18
Slow ring: –
New features
Antimalware
Linux endpoints now support adding hash values to the Blocklist in the Incidents section. To read more, refer to the Add rules to the Blocklist > Adding hash values to the Blocklist section on the Blocklist page.
Important
This functionality is available only with specific kernels. For more information, refer to Linux kernels supported by Blocklist and Application Blacklisting.
This is an Antimalware functionality. The EDR Sensor is not required in the installation package.
Any blocking rule applied to Linux containers will be ignored. Applications on the container host can be blocked by hash.
Adding application paths and connections to the Blocklist is not currently supported.
Linux endpoints now support configuring Application Blacklisting in the Network Protection > Content Control > Application Blacklisting section within the policy settings. To read more, refer to the Application Blacklisting section on the Content Control page.
Important
This functionality is available only with specific kernels. For more information, refer to Linux kernels supported by Blocklist and Application Blacklisting.
This is an Antimalware functionality. The Content Control is not required in the installation package.
Any application rule applied to Linux containers will be ignored. Applications on the container host can be blocked by path.
Scripts can be blocked by path only when they are executed directly, not explicitly loaded by an interpreter. They can start with a shebang or they can be shell scripts without a shebang.
Added support for upcoming features available with the next major GravityZone release.
Container Protection
Added support for upcoming features available with the next major GravityZone release.
Improvements
Antimalware
Optimized the antimalware scanning mechanism to minimize system boot delays when scheduled scans are missed.
All on-demand scan tasks now have the Preserve last access time setting available on Linux endpoints, too. Read more: Malware scan.
Security Container
You can now configure an optional group ID (
GID
) parameter when deploying Bitdefender Security Containers on a Linux container host. This prevents potential issues caused by the default GID 10000 already being used.Added support for the following container platforms:
Openshift (4.13 – 4.17.2)
RKE2 (2.8)
Product
Added support for the following distributions:
Zorin OS
SLES 15 SP6
Linux Mint Debian Edition 6
Resolved issues
Endpoint Detection and Response
Fixed an issue that caused a size increase of the /opt/bitdefender-security-tools/var/edrsubmitter/
directory up to 4 GB.
Antimalware
Resolved an issue causing
bduitool get ps
to display the status of an unsupported feature.Fixed a bug that caused
/bin/bash
to be wrongly reported as malware inside containers.
Known issues
Antimalware
On the Blocklist page, scripts can be blocked by hash only if they start with a shebang (
#!
).In the Application Blacklisting policy section, applications can be blocked only with the Block All option selected. Blocking rules for scheduled applications are not saved.
On-access exclusions take priority over blocking rules. Any application specified in a blocking rule will not be blocked if:
Its location is excluded from on-access scanning as an object of type Folder.
It is excluded from on-access scanning as an object of type File.
Its extension is excluded from on-access scanning.
It is accessed by a process excluded from on-access scanning as an object of type Process.
Version 7.3.0.200172
Release date:
Fast ring: 2024.10.31
Slow ring: 2024.11.04
Resolved issues
Endpoint Detection and Response
Fixed an issue that caused the /opt/bitdefender-security-tools/var/edrsubmitter/
directory to increase to 4 GB.
Version 7.2.1.200170
Release date:
Fast ring: 2024.10.03
Slow ring: 2024.10.07
Resolved issues
Internal bugs have been resolved.
Version 7.2.1.200168
Release date:
Fast ring: 2024.09.18
Slow ring: 2024.09.19
Resolved issues
Security Telemetry
Resolved an issue where BEST would repeatedly crash if the SIEM server URL, configured in General > Security Telemetry > SIEM Connection Settings within the policy settings, was invalid or incorrectly formatted.
Update server
Fixed an issue where changing the URLs in Relay > Update > Update Locations within the policy settings had no effect.
Version 7.2.1.200164
Release date:
Fast ring: 2024.09.04
Slow ring: 2024.09.09
New Features
Security Telemetry
When MDR is enabled, you can now send telemetry data simultaneously to the MDR team and to your own SIEM server configured in the General > Security Telemetry policy section.
Product
Added support for upcoming features available with the next major GravityZone release.
Resolved issues
Product
VirtualBox no longer crashes due to uprobes when you try to run a virtual machine on an endpoint with BEST installed.
Tasks
Resolved an issue where BEST failed to consider whether the Reconfigure task used the proxy setting from the update location.
Version 7.2.0.200144
Release date:
Fast ring: 2024.07.29
Slow ring: 2024.08.05
New Features
Endpoint Detection and Response
Added support for upcoming features available with the next major GravityZone release.
Improvements
Endpoint Risk Analytics
Any Endpoint Risk Analytics scan that fails, is interrupted, or is incomplete is now automatically retried three times.
Resolved issues
Product
Added kprobes support for kernel
6.9.3-76060903-generic
.The GDB debug tool no longer gives
SIGTRAP
error when Bitdefender Endpoint Security Tools for Linux is installed on SUSE Linux Enterprise 15.0, SUSE Linux Enterprise 15.1, or openSUSE Leap 15.0 systems.
Version 7.1.1.200141
Release date:
Fast ring: 2024.06.10
Slow ring: 2024.06.11
Resolved issues
Security fixes
Version 7.1.1.200135
Release date:
Fast ring: 2024.05.30
Slow ring: 2024.06.04
New Features
Advanced Threat Control
Bitdefender Advanced Threat Control is now available for Linux in report-only mode. This means that whether the preferred security level is Aggressive, Normal, or Permissive, the module takes no action except to report the infected applications detected by Bitdefender.
It can be installed at the creation of a new installation package, by selecting the Advanced Threat Control option. Learn more.
Resolved issues
Product
Added On-Access compatibility for kernels
2.6.32-754.50.1.el6.x86_64.rpm
and2.6.32-754.53.1.el6.x86_64.rpm
.Cloud Services are now accessible when the DNS server is not configured and the relay is used as a proxy.
Version 7.1.0.200110
Release date:
Fast ring: 2024.04.16
Slow ring: 2024.04.23
New Features
Security Telemetry
You can now forward security telemetry events from Linux endpoints to a syslog server in JSON format.
Tip
You can enable this feature on Linux endpoints from the General > Security Telemetry > SIEM Connection Settings section of the policies applied to them. Learn more.
Improvements
Product
Reduced the Bitdefender Endpoint Security Tools installation time for virtual machines that are hosted on premises.
Optimized the hard disk space occupied by the agent. Unnecessary files are automatically deleted after installation.
Antimalware
On-Demand scans now consume less RAM and swap space.
Added support for upcoming features available with the next major GravityZone release.
Patch Management
Updated libicu to the latest versions corresponding to the supported distributions by the Patch Management feature.
Warning
For SLES 15 operating systems, Patch Management now supports only SLES 15 SP5 or higher.
Resolved issues
Antimalware
Resolved the timeout error at the bduitool get scanlog
command. Now the command completes in less than 60 seconds. In lack of previous scan tasks, the command will finish without any message.
Endpoint Detection and Response
The Endpoint Detection and Response module no longer causes high CPU usage due to processing unnecessary events. For these events, we have added exclusions.
Version 7.0.5.200090
Release date:
Fast ring: 2024.03.07
Slow ring: 2024.03.11
Important
This update includes all improvements and fixes from version 7.0.5.200087, released on fast ring.
Resolved issues
Security fixes
Version 7.0.5.200087
Release date:
Fast ring: 2024.02.29
Slow ring: -
Resolved issues
Resolved an issue causing increased CPU usage on Red Hat Enterprise endpoints running with the EDR Sensor module installed.
Security fixes
Version 7.0.5.200075
Release date:
Fast ring: 2024.02.06
Slow ring: 2024.02.13
Improvements
Added support for the Pop!OS operating system with kernel version 6.6.6-76060606-generic.
Resolved issues
You can now properly install and use the Patch Management module on endpoints with SUSE Linux Enterprise Server 15 SP5.
Malware detections on virtual machines are now properly transmitted and displayed under Incidents, Threats Xplorer, Executive summary and the Security audit report. The issue sometimes occurred when Container Protection was not installed on the machine.
Resolved an issue causing Malware Status reports to be displayed under Scan Logs when viewing endpoint details from the Network page.
Fixed an issue causing scans to add folder and subfolder paths to scan lists despite being excluded in the policy applied to the endpoint. This was causing increased RAM usage.
Security fixes
Version 7.0.5.200049
Release date:
Fast ring: 2023.12.11
Slow ring: 2023.12.12
Important
This update includes all improvements and fixes from version 7.0.5.200046 released on fast ring.
Improvements
Stability fixes.
Version 7.0.5.200048
Release date:
Fast ring: 2023.12.06
Slow ring: -
Improvements
Security and stability fixes.
Version 7.0.5.200046
Release date:
Fast ring: 2023.12.04
Slow ring: -
Improvements
Incidents are now created when Integrity Monitoring rules with the critical severity level are triggered.
BEST for Linux is now limited at using 50% of an endpoint's CPU usage when performing On-Demand scans with low priority.
The Paused/Suspended, and Stopped statuses are now available for container endpoints when displayed in the the GravityZone console.
BEST for Linux is now compatible with the following distributions:
Fedora 39 x64
OpenSUSE Leap 15.5 x64
You can now use
**
wild card exclusions for On-Access scans. The feature works for both files and folders.
Resolved issues
BEST for Linux now properly identifies Amazon Web Service EC2 with IMDSV2 when deployed with the automatic scan mode.
On-Access scans that run on container hosts with BEST for Linux deployed with Container protection now exclude folders where container engines unpack image layers and mount overlay file systems.
Fixed an issue where Docker container namespaces were still protected by BEST for Linux after the container was removed.
Incidents now show the correct action taken for events where items were quarantined as a result of a malware detection.
Version 7.0.3.2322
Release date:
Fast ring: 2023.11.16
Slow ring: 2023.11.16
Resolved Issues
Resolved an issue causing some security updates to fail when performed through a Relay.
Version 7.0.3.2319
Release date:
Fast ring: 2023.11.13
Slow ring: 2023.11.14
Resolved Issues
Resolved an issue causing some log files to be mistakenly generated in the "/" directory during security updates.
Security fixes
Version 7.0.3.2312
Release date:
Fast ring: 2023.11.13
Slow ring: -
Resolved Issues
Security fixes
Version 7.0.3.2271
Release date:
Fast ring: 2023.09.04
Slow ring: 2023.09.07
New features
Added support for upcoming features available with the next major GravityZone release.
Resolved issues
The Network Attack Defense module no longer blocks SSH connections with other endpoints.
Known issues
Custom detection rules that have a Parent Name matching criteria with a wildcard currently do not work.
The Antimalware feature does not currently work on CentOS 7 operating systems using ARM architectures (aarch64).
Version 7.0.3.2248
Release date:
Fast ring: 2023.08.17
Slow ring: -
New features
Added support for upcoming features available with the next major GravityZone release.
Resolved issues
The Network Attack Defense module no longer blocks SSH connections with other endpoints.
Known issues
Custom detection rules that have a Parent Name matching criteria with a wildcard currently do not work.
The Antimalware feature does not currently work on CentOS 7 operating systems using ARM architectures (aarch64).
Version 7.0.3.2239
Release date:
Fast ring: 2023.07.25
Slow ring: 2023.07.26
Improvements
Security fixes
Version 7.0.3.2225
Release date:
Fast ring: 2023.07.13
Slow ring: 2023.07.24
New features
You can now upload and download files when using the Remote Shell feature on Linux endpoints. Learn more
You can now cancel any ongoing or pending file transfers resulted from the use of the Remote Shell feature.
The Delete all button is now available: all the entries will be removed from the Investigation grid and all pending or ongoing downloads will be canceled.
Improvements
BEST for Linux v7 is now compatible with the following distributions:
Kylin v10 x64 (RPM-based)
SLED 15 SP4 x64
Ubuntu 23.04 x64
Ubuntu 22.10 x64
Debian 12 x64
Fedora 38 x64
BEST for Linux us now compatible with ARM architecture (aarch64).
The curl table used by the Live Search feature is now disabled on endpoints with BEST for Linux installed. This was done to protect against exploits involving lateral movement attacks.
Added the efivar library in BEST for Linux packages, covered under GNU Lesser General Public License, version 2.1.
Resolved issues
Removed support for several DazukoFS module kernel archives. The following archives are still supported:
2.6.32-754.35.1.el6.x86_64
2.6.32-754.35.1.el6.centos.plus.x86_64
2.6.32-754.35.1.el6.i686
2.6.32-754.35.1.el6.centos.plus.i686
Updated the OpenSSL library to version
1.1.1u
.Updated libssh library to version
0.10.5
.Endpoints using the Network Attack Defense feature now use the netfilter conntrack helper component to avoid routing all ports for FTP connections.
Network Attack Defense no longer blocks access to the Oracle MySQL Workbench 8.0.29 database when deployed with BEST for Linux.
Resolved an issue causing File, Folder or Process scanning exclusions to not include subfolders when a
/
is added at the end of the folder path.Launching BEST for Linux now properly cleans Bitdefender AuditD rules at startup.
Downloading an installation kit on a relay now properly removes older kits from the endpoint. An issue was causing the maximum number of kits that are allowed on a relay endpoint to be exceeded by 1.
Fixed an issue causing endpoints with BEST for Linux to display the
Connection to the Cloud services cannot be established
notification, despite it being disabled from the policy applied on the endpoint. The setting can be found under General > Notifications > Endpoint Issues Visibility > Modular Settings > Cloud Services notifications.Endpoints with BEST for Linux installed are no longer connecting directly to the GravityZone cloud services despite them being configured to connect through a proxy.
On-demand scans are no longer interrupted when performed on archives larger than 4 GB.
Fixed an issue which could lead to potential deadlocks within the EDR module.
BEST for Linux now stops querying update servers once a connection is established.
Fixed an issue causing BEST for Linux updates to fail, returning
error 403
.Failed product updates now properly fall back to the next available update server.
Removed features
Removed support for Patch Management for the following distributions:
RedHat 6
CentOS 6
Known issues
Decrypting documents downloaded from Remote shell sessions returns an error (
decryption forced to fail!
), despite the decryption being successful.BEST for Linux sometimes fails to start after the endpoint where it is deployed is upgraded from init.d to systemd. To resolve this issue refer to this article.
Remote shell sessions are currently not displaying certain special characters.
Moving to the
/opt/bitdefender-security-tools/
directory during a remote shell session incorrectly returnserror 123
instead oferror 313
.Trying to use a read-only network mount as an upload path during a remote shell session incorrectly returns
error 0
instead of error5 - access denied
.
Version 7.0.3.2193
Release date:
Fast ring: 2023.05.15
Slow ring: 2023.05.17
Resolved issues
BEST updates no longer refresh update repositories on SLES operating systems.
Fixed an issue causing BEST to mount NFS shares as a result of on-demand scans.
Updating BEST no longer restores NAD module script execution rights to default.
Improvements
On-demand scans that run with low priority now only use half of available endpoint resources.
Version 7.0.3.2177
Release date:
Fast ring: 2023.04.11
Slow ring: 2023.04.19
Improvements
BEST for Linux is now compatible with the PopOS and Amazon Linux 2023 distributions.
KProbes now support security content update rings.
You can now use On-Access scanning for files in the root (
/
) directory on containers protected by BEST.The Support Tool now gathers additional logs.
You can now use the Support Tool with Bitdefender Security for Containers.
Added support for upcoming features available with the next major GravityZone release.
Security containers are now deployed in a dedicated namespace on Kubernetes:
bitdefender-security-container
.Security containers now use a dedicated Kubernetes service account:
bitdefender-security-container
.
Removed features
All RHEL and RHEL derivatives (for example, CentOS and Oracle) prior 6.10 are no longer supported.
Limitations
Deploying Security Containers on OpenShift 4.12 and later environments using the Helm package manager is currently unsupported.
Resolved issues
Fixed multiple compatibility issues between BEST for Linux and NFS mounts.
Security and stability fixes.
Version 7.0.3.2120
Release date:
Fast ring: 2023.01.31
Slow ring: 2023.02.07
Resolved issues
Endpoints with the Network Attack Defense module deployed are no longer experiencing connectivity issues.
Reconfigure client tasks configured with the Match List option no longer fail when the endpoints are communicating through a Relay.
Fixed an issue causing the Antimalware module to sometimes crash when performing On-access scan tasks.
Deploying BEST for Linux on endpoints not using the default package manager of their operating system no longer fails.
Version 7.0.3.2115
Release date:
Fast ring: 2022.12.12
Slow ring: 2022.12.15
New features
Outbound monitoring is now available for Network Attack Defense on Linux endpoints.
Improvements
Added support for Oracle Linux 8 and Oracle Linux 9 5.15 kernel versions.
DNF is now the first choice package manager for YUM based operating systems when installing and updating BEST for Linux.
Resolved issues
Reconfigure Client tasks with Match List option selected now properly execute for endpoints with a Linux Relay set as an update location. The tasks used to fail, returning a
no suitable update server found
error.The EDR module no longer causes increased CPU usage when enabled.
Fixed an issue causing endpoints with BEST for Linux installed not to appear in the Active Directory tree.
Version 7.0.3.2106
Release date:
Fast ring: 2022.11.21
Slow ring: 2022.11.21
Improvements
Security fixes
Version 7.0.3.2104
Release date:
Fast ring: 2022.11.16
Slow ring: 2022.11.17
Improvements
Added support for upcoming features available with the next major GravityZone release.
KProbes are now available for Linux kernel 6.0.
Security fixes.
Version 7.0.3.2085
Release date:
Fast ring: 2022.10.13
Slow ring: 2022.10.17
Improvements
On demand scans are now available for autofs network shares.
Network Attack Defense now runs as a separate process. This will considerably improve stability.
The process exclusions from your GravityZone policies now apply to EDR events from endpoints with BEST for Linux installed.
You can now define assignment rules based on endpoint hostname.
Live Search now returns a limited amount of information to GravityZone from endpoints with BEST for Linux deployed. The total number of rows generated by the search is included in the response.
Resolved issues
Fixed an issue causing Container Protection to only scan the first two levels of a file path.
Product updates on SLES 12.5 are no longer failing due to zypper license agreement.
Product updates now properly ignore global
apt
proxy settings.
Version 7.0.3.2061
Release date:
Fast ring: 2022.09.12
Slow ring: 2022.09.19
Improvements
Added support for additional Fedora kernels. Learn more
Resolved issues
Security fixes
Version 7.0.3.2050
Release date:
Fast ring: 2022.08.16
Slow ring: 2022.08.16
Resolved issues
The files used by BEST for Linux when EDR is enabled through AuditD now revert to default when no longer needed. This occurs when EDR is disabled or when kprobes are used instead of AuditD.
Version 7.0.3.2038
Release date:
Fast ring: 2022.08.03
Slow ring: 2022.08.03
Resolved issues
Fixed an issue causing security updates to fail and increase CPU usage in certain situations.
Version 7.0.3.2034
Release date:
Fast ring: 2022:08.01
Slow ring: 2022:08.02
Important
This update includes all improvements and fixes from version 7.0.3.2030 released on fast ring.
Resolved issues
Security fixes
Version 7.0.3.2030
Release date:
Fast ring: 2022.07.28
Slow ring:
New features
The Network Attack Defense module is now available for Linux. Learn more
EDR Custom rules are now applicable to endpoints with BEST for Linux v7.
Improvements
BEST for Linux v7 is now compatible with the following distributions:
CBL-Mariner 2
Ubuntu 22.04
Red Hat Enterprise Linux 9
AlmaLinux 9
Fedora 36
Added support for the Amazon Linux 2 5.10.x and 5.15.x kernel versions.
Antimalware engines are no longer loaded when on-access scanning is disabled. This feature does not apply to endpoints where the Container Protection module is installed.
Resolved issues
The Security Telemetry feature now properly displays the connection status to the telemetry servers.
BEST for Linux no longer causes high CPU usage when EDR is enabled.
Fixed issue causing servers with BEST for Linux to freeze. This was caused by resetting the firewall while using central scan with a hybrid fallback.
Using BEST for Linux with AuditD on systems running on Red Hat Enterprise Linux Server 6.7 no longer causes high resource usage.
Closing BEST for Linux v7 now properly terminates the active instance of the program.
Fixed issue causing BEST for Linux v7 to gradually increase RAM usage over time.
Known issues
Starting or stopping Network Attack Defense will reset all active connection done through ports 21 and 22.
Version 7.0.3.2004
Release date:
Fast ring: 2022.05.12
Slow ring: 2022.05.12
Resolved issues
On-Demand scanning tasks with low priority no longer cause high CPU usage.
Assignment rules based on location now properly apply policies to the target IP addresses.
Quarantined items are now automatically removed as per the policy configuration.
Version 7.0.3.1999
Release date:
Fast ring: 2022.05.09
Slow ring: 2022.05.10
Improvements
The Send feedback regarding security agents’ health and Use Bitdefender Global Protective Network to enhance protection policy options now also apply to endpoints with BEST for Linux deployed. You can find the options under General > Settings > Options when editing a policy.
EDR Custom Rules are now applicable on endpoints where BEST for Linux is deployed.
Resolved issues
Installing BEST for Linux v7 on an endpoint no longer overwrites the locally configured OSQuery service.
Deploying BEST for Linux on an Amazon Linux Docker environment no longer causes an increased resource usage.
Fixed an issue that was affecting the communication between BEST for Linux and GravityZone due to an improper integration with Active Directory.
Deploying BEST for Linux on an Red Hat Enterprise environment no longer causes increase CPU usage.
Version 7.0.3.1986
Release date:
Fast ring: 2022.04.04
Slow ring: 2022.04.06
Important
This update includes all improvements and fixes from versions 7.0.3.1982 and 7.0.3.1984 released on fast ring.
Resolved issues
Resolved a critical issue occurred after the last product update.
Version 7.0.3.1984
Release date:
Fast ring: 2022.03.31
Slow ring: -
Resolved issues
Fixed a configuration problem for BEST Relay.
Version 7.0.3.1982
Release date:
Fast ring: 2022.03.31
Slow ring: -
New features
Patch Management now supports Smart Scan on Linux.
Added support for Investigation packages for both BEST for Linux v7 and SDK.
Improvements
BEST for Linux is now compatible with Linux Mint and Miracle Linux.
Deploying or updating BEST for Linux with EDR using Linux AuditD now automatically updates configuration files.
Added support for the Shut down computer when scan is finished option scan option.
Memory usage has been optimized when using system's AuditD.
EDR events generation has been optimized.
Added detection for the exploitation of the CVE-2022-0847 vulnerability.
Information on errors related to Patch Management is now available here.
Improved product description in Docker Hub.
Resolved issues
BEST for Linux now detects Linux AD integrations.
Attempting to enable SSL on certain server types no longer causes an indefinite retry loop. This would also cause log files to be flooded with error messages.
Fixed issue causing high CPU usage on systems with BEST for Linux using AuditD.
Java applications no longer slow down after installing BEST for Linux on endpoints running on the RHEL 7 and RHEL 8 operating systems.
Using a script to write files in a high number simultaneously no longer causes high CPU utilization.
Resolved issue causing high CPU utilization when using EDR.
Custom Scan tasks no longer scan shared file paths when the Scan network share option is not selected.
Fixed issue causing On-Access scans to miss threats during performance tests.
CIFS and NFS protocols are no longer restricted for systems that use the Fanotify notification system.
Fixed issue causing On-Demand scan task reports to fail to register in logs.
On-Demand scan logs from endpoints with BEST for Linux v7 now appear properly in Control Center.
Known issues
On-Access scanning does not detect threats in network paths mounted using Amazon EFS.
Version 7.0.3.1956
Release date:
Fast ring: 2022.03.10
Slow ring: 2022.03.10
Improvements
Reduced memory consumption in certain scenarios where EDR is active.
Version 7.0.3.1948
Release date:
Fast ring: 2022.02.17
Slow ring: 2022.02.21
Improvements
Optimized the error logging and update mechanisms.
Version 7.0.3.1942
Release date:
Fast ring: 2022.02.07
Slow ring: 2022.02.07
Resolved issues
Fixed an issue causing slow product initialization.
Version 7.0.3.1941
Release date:
Fast ring: 2022.02.03
Resolved issues
Linux machines integrated into Active Directory are now being properly detected and appear under the GravityZone console.
Applying policies no longer generates unnecessary EDR related events causing high CPU usage. This was occurring due to EDR events remaining active while the EDR Sensor was disabled and Advanced Anti-Exploit remained enabled.
The
bdsecd
process used for debug logging no longer causes high CPU usage
Version 7.0.3.1927
Release date: 2021.12.24
Resolved issues
All events are now being sent to Splunk servers.
Known issues
Event submissions to Splunk servers currently fail without a fully signed SSL certificate.
Version 7.0.3.1922
Release date: 2021.12.16
New features
Patch Management is now available for BEST for Linux. You can find a list of compatible operating systems here.
Improvements
You can now schedule recurring product and security content updates to run on endpoints. You can set the task to run on a specific day of the week or after a certain time has passed since the last occurrence.
A notification is now sent when a system restart is required. You can choose to immediately restart or postpone the process.
You can now enable an automatic shutdown or system restart based on specific scenarios such as product update or disinfection.
The Restart machine task is now available for Linux endpoints.
Antimalware events history is now available locally.
Resolved issues
Updating BEST for Linux now properly deletes all previous installation packages present on the endpoint.
Resolved multiple issues causing the security agent to crash or freeze.
All scan tasks ran through the Bitdefender User Interface Tool (
bduitool
) now receive unique IDs.
Version 7.0.3.1903
Release date: 2021.12.01
Improvements
Product update mechanism via our agent installer has been enhanced.
Version 7.0.3.1899
Release date:
Fast ring: 2021.11.23
Slow ring: 2021.11.25
Improvements
Product
You can now apply policies based on location assignment rules.
BEST for Linux v7 is now compatible with the following Linux distributions:
Rocky Linux 8.x
Pardus 21.0x
Alma Linux 8.x
Ubuntu 21.04 & 21.10
Cloud Linux OS
BEST for Linux v7 is now compatible with 32-bit operating systems on the following distributions:
CentOS 6
CentOS 7
CentOS 10
Debian 11
Debian 9
Red Hat Enterprise Linux 6
Ubuntu 14
Ubuntu 16
BEST for Linux v7 now supports DazukoFS for kernel versions 2.6.32.
Note
As a result of these improvements, feature parity between versions 6 and 7 has been achieved.
Resolved issues
Product
BEST for Linux v7 installer no longer incorrectly reports that there is not enough space on disk when the
/opt/bitdefender-security-tools
file exists.Starting an installation of BEST for Linux v7 on an endpoint with an older version of v7 installed no longer returns "The product is already installed".
Fixed the issue causing increased RAM usage on Ubuntu machines.
Product updates no longer fail when the Relay URL address has a slash (
/
) at the end.Running the
deliverall
command no longer archives thednf
folder on machines where BEST for Linux v7 has been updated from an older version.Product updates no longer fail on SUSE operating systems.
Updating BEST for Linux v6 to v7 now properly creates the
/usr/bin/bd symlink
file.
Support Tool
Troubleshooting Debug session tasks no longer remain in an In progress state.
Advanced Anti-Exploit
Alerts are no longer incorrectly triggered for
pkexec
andpolicykit
processes.
Version 7.0.3.1869
Release date: 2021.11.16
Resolved issues
Product
Security fixes
Version 7.0.3.1868
Release date: 2021.11.03
Resolved issues
Product
Background periodic clean-up of temporary support files no longer causes Bitdefender systems to crash.
Version 7.0.3.1862
Release date: 2021.10.28
Resolved issues
Product
Security content updates no longer cause scan servers to reload.
Repeated deployments via Relay on the same endpoint no longer apply the same BEST version. This would occur regardless of the specified deployment settings.
Resolved an issue causing the Quarantine module to fail clearing file descriptors during scans, resulting in higher resource usage.
Improvements
On-Access
Files previously confirmed as clean and unmodified are no longer scanned when accessed.
Version 7.0.3.1850
Release date:
Fast ring: 2021.10.21
Slow ring: 2021.10.25
Improvements
Product
Support Tool is now available for BEST for Linux v7.
Container Protection
On-Access protection is now available for Security Container Hosts.
Container Protection is now compatible with OpenShift CRI-O Container Engine.
Resolved issues
Product
Installing BEST for Linux on an VM with an RPM-based OS after clearing the
yum
cache no longer fails when no internet access is available.
Known issues
Product
During scans, the Quarantine module does not clear file descriptors, resulting in higher resource usage.
Version 7.0.1.1774
Release date:
Fast ring: 2021.10.04
Slow ring: 2021.10.05
Resolved issues
Product
(
bduitool
) is now available for BEST for Linux v7.Bitdefender user no longer appears in GNOME GUI environments.
BEST for Linux v7 no longer takes ownership of certain APT files, making software updates to fail.
Known issues
On-demand
Changing the system time on an endpoint that has scheduled custom scans causes Bitdefender product to crash.
Version 7.0.1.1762
Release date: 2021.09.29
Resolved issues
Product
Kprobes is no longer failing to load after security content updates.
Fixed issue causing update tasks run on machines with BEST for Linux v7.0.1.1626 installed to fail despite the console showing the update as successful.
Version 7.0.1.1754
Release date: 2021.09.23
Improvements
Product
Logs folder location has been changed from
/tmp
to/opt/bitdefender-security-tools/var/tmp
.Network Isolation tasks now work on endpoints which have a proxy configured.
Support tool is now available for BEST for Linux v7. It is currently available only from the command line interface.
EDR
The performance of the incidents sensor has been increased by as much as 30% in certain scenarios.
Extended the EDR support to Amazon Bottlerocket.
Resolved issues
Product
Policies now correctly apply communication settings to endpoints that have been upgraded from BEST for Linux v6 to v7.
GravityZone now properly detecting new deployments of Patch Management.
Running a Reconfigure Client task now correctly checks available disk space before installing a Relay role. The installation will only begin if sufficient disk space is available.
Uninstalling BEST for Linux v7 from virtual machines no longer results in a crash in certain situations.
BEST for Linux v7 now properly updating on all SLES machines.
Running BEST for Linux installation packages downloaded from a custom host no longer fail.
BEST for Linux v7 now compatible with machines working with FIPS protocol.
Fixed issue causing policies not to apply correctly when done through a Relay.
Security fixes.
Advanced Anti-Exploit
Custom scan exclusions now properly loading.
On-Access scans no longer scan removed scan paths specified in your policy settings.
Added exceptions for alerts related to package managers (apt, yum, dnf).
Techniques are now properly displayed for corresponding generated events.
Container Protection
Container logs now properly record Security Container updates.
Restoring a quarantined file to a container now correctly places the file back on the container instead of the host VM.
Security Containers now work properly with Bottlerocket OS.
Version 7.0.1.1725
Release date: 2021.09.09
Resolved issues
Antimalware
Security content updates no longer cause On-Demand scans to return no results.
Version 7.0.1.1713
Release date: 2021.09.07
Improvements
Network Isolation for EDR is now available.
Resolved issues
Product
Upgrading BEST for Linux from v6 to v7 no longer causes issue where both BEST versions run on the same endpoint.
Upgrading BEST for Linux from v6 to v7 no longer causes On-Demand scans to return no results.
Relay role
The Relay role is now supported again.
Known issues
Network Isolation disconnects endpoints from the network, causing a loss of connectivity with GravityZone. This issue only occurs for endpoints that use policies with proxy configurations.
Note
To change the proxy settings, go to the General > Communication policy section and choose another option for Communications between Endpoints and Relays / GravityZone.
Version 7.0.1.1626
Release date: 2021.08.12
Resolved issues
Product
Policies applied to Security Containers now function independently of policies applied to the host.
Enabling On-Access on policies that have already been applied no longer fails to activate the service.
HTTPS protocol updates no longer fail on certain operating systems.
Running an Update client task for both product and security content no longer fails to perform the security content update.
Scan reports now show the correct number of scanned files.
Version 7.0.1.1582
Release date: 2021.08.12
Improvements
Container Protection
Podman inventory support now available.
Resolved issues
Product
Update tasks now show correct status after failing.
Using On-Access scanning on a Ubuntu container no longer causes Bitdefender services to sometimes crash.
Issues no longer appear when trying to remove malware from certain archives.
Container Protection
Container runtime now registers properly in all environments.
When applying policies to containers, configured actions now apply correctly when malware is detected, including on older kernel versions.
Kprobes no longer being reloaded when no new updates are available.
Version 7.0.1.1556
Release date: 2021.08.06
Resolved issues
Product
Product updates no longer failing when no update locations are added to the policy you are using.
Version 7.0.1.1551
Release date: 2021.08.05
Resolved issues
Product
Product now correctly showing status for disabled modules.
Performing a scan task during a security content update no longer causes Bitdefender services to sometimes crash.
Using a proxy server no longer prevents EDR incidents from being generated.
Version 7.0.1.1520
Release date: 2021.07.29
BEST for Linux v7 is now available with a new set of features and benefits, including:
Features
Container Protection – protects both the container host and its running containers.
A new anti-exploit module.
Benefits and improvements
A new architecture, created using Kprobes instead of kernel modules, which eliminates the common delays or the need to sacrifice security when upgrading.
Greatly expanded platform compatibility to all Enterprise Linux distributions and cloud native Linux distributions.
Known issues
Policy per location not supported.
Bduitool
not supported.Relay role not supported.
Remote troubleshooting not supported.
Has issues status not being removed properly from endpoints once the issue has been resolved.
SELinux not supported.
EDR Isolate action not supported.
Shut down computer when scan is finished option not functioning properly after scan is performed. Endpoints are not being shut down.
Restart computer task with Restart now option enabled not functioning properly. Virtual machines and computers are not being restarted.
Files in mounted network directories not being scanned through On-Access scanning.
Machines with 32-bit OS not supported.
Delay in security content update status change after security update.
On-Access scanning ignoring file size limitation. All file sizes are scanned.