Release v1.5.1
    • 04 Apr 2024
    • 1 Minute to read
    • PDF

    Release v1.5.1

    • PDF

    Article summary

    Docker tag: 1.5.1-19963

    Bugs

    • We are aware of an issue with sensor degradation on Linux EDR sensors using auditD as their telemetry collection method. Since we are only seeing this on those sensors we recommend that you use eBPF as the preferred telemetry source in the meantime.

    Fixed

    • Audit telemetry: Handle audit events from filemod in Oracle kernels that deviate from mainline.

    • Audit telemetry: Properly handle creation of symlinks that target themselves.

    Changed

    • Audit telemetry: Ignore renames of hardlinked files (when hardlinked to each other).

    • eBPF telemetry: Does not emit warnings for files not being tracked.

    Hashes

    MD5

    3cdd7195a29cba48c1dc371a53f00d9d  x86_64/cfsvcd
    d8d57fd39bc427d356d65d34d09e68bf  x86_64/cwp-launch
    6650b2caded5f53874811a1d28c41a1d  aarch64/cfsvcd
    16f51d7d07696514e9154bd89fbb71de  aarch64/cwp-launch

    SHA256

    402cee39b0ee861a0a0ccc6cec9232ee665f7ccef008bc8ee53772546b4e56e9  x86_64/cfsvcd
    11ce94e66f138ca130698d0c0c0ef0cd84d6be21dc4e5f39a0bce726e0b4460d  x86_64/cwp-launch
    0f9a58f9513ea84d7a872f6f530d483c514da9e2f15ca66084ab5e087b364f7e  aarch64/cfsvcd
    e900917d1903d196fb9ed351b719b9c0ade9c077a988d45f6a5a69afe880470e  aarch64/cwp-launch


    Was this article helpful?

    What's Next