The Trellix Application and Change Control 6.6.4 Linux release includes new features, resolved issues, updated kernels and platform support.
Every update release is cumulative and includes all features and fixes from the previous release. We recommend that you always upgrade to the most current update.
Rating
The rating defines the urgency for installing this update.
This release is recommended for all environments. Apply this update at the earliest convenience.
Release details
For release dates and build numbers, see KB87944.
Upgrade support
This release supports upgrading from the following Application Control client versions:
6.1.0–6.1.7
6.2.0
6.3.0
6.4.0–6.4.24
6.5.0–6.5.2
6.6.0–6.6.3
New or changed
Command-Line support in S3diag—This release adds command-line functionality in S3diag to recommend the updater list.
Enhanced logging for deny events—This release adds grandparent and great-grandparent process names to the existing log details in Solidcore.log and S3diag.log for denial events such as Deny_write, Deny_read, and Deny_exec.
Changes to execution policy in observe mode—This release bans executing a process in observe mode if the 'Deny_exec' policy applies to a process with the denial reason, BAN BY CHECKSUM.
Support for syscall hooking in kernel—This release adds support for syscall hooking in kernel versions above 6.6.26, improving compatibility and extending functionality with newer Linux kernels.
OpenSSL upgrade—This release upgrades the OpenSSL version to 3.0.14.
Support for SHA256 inventory hashing—This release introduces SHA256 inventory hashing support in TACC Linux, improving the system's security and data integrity capabilities.
Libcurl upgrade—This release upgrades the Libcurl version to 8.9.1.
New kernel support—This release supports the latest versions of the Linux kernel and other platforms:
Debian 12
6.1.0-20-amd64
6.1.0-22-amd64
6.1.0-23-amd64
SLES 15
5.14.21-150500.55.65-default
Oracle 7
5.4.17-2136.333.5.el7uek.x86_64
Oracle 9
5.15.0-207.156.6.el9uek.x86_64
Ubuntu 18
4.15.0-222-generic
4.15.0-223-generic
4.15.0-224-generic
4.15.0-225-generic
Ubuntu 20
5.4.0-170-generic
5.4.0-171-generic
5.4.0-172-generic
5.4.0-174-generic
5.4.0-182-generic
5.15.0-97-generic
5.15.0-100-generic
5.15.0-101-generic
5.15.0-102-generic
5.15.0-105-generic
Ubuntu 22
5.15.0-97-generic
5.15.0-100-generic
5.15.0-101-generic
5.15.0-102-generic
5.15.0-105-generic
Amazon Linux 2
5.15.152-100.162.amzn2.x86_64
5.15.153-100.162.amzn2.x86_64
5.10.213-201.855.amzn2.x86_64
5.10.214-202.855.amzn2.x86_64
5.10.215-203.850.amzn2.x86_64
5.10.216-204.855.amzn2.x86_64
5.10.217-205.860.amzn2.x86_64
5.10.218-206.860.amzn2.x86_64
5.10.218-208.862.amzn2.x86_64
5.4.273-186.370.amzn2.x86_64
5.4.274-187.369.amzn2.x86_64
5.4.275-189.375.amzn2.x86_64
5.4.276-189.376.amzn2.x86_64
5.4.277-190.375.amzn2.x86_64
4.14.343-259.562.amzn2.x86_64
4.14.343-260.564.amzn2.x86_64
4.14.343-261.564.amzn2.x86_64
4.14.344-262.563.amzn2.x86_64
4.14.345-262.561.amzn2.x86_64
For the complete list of kernels supported, see Linux kernel support for Application and Change Control 6.x.
Known issues
For a list of current known issues, see Application and Change Control 6.x Known Issues.
Resolved issues
This release resolves known issues.
Category | Reference | Resolution |
|---|---|---|
Fixes to features | MACC-13072 | Containers and pods now run successfully with TACC Linux enabled. This update expands support to include container runtimes such as Containerd, CRI-O, and Docker, as well as pods orchestrated by Kubernetes. |
Fixes to features | MACC-13422 | The execution of |