The new docs.trellix.com offers a modernized UI and AI-powered features like conversational searches. Content is currently available only in English. Other languages will be available in mid-October 2026. We hope you enjoy the new experience.

Trellix Endpoint Security (ENS) for Linux 26.8 August Kernel - Update

Prev Next

The Trellix Endpoint Security (ENS) for Linux 26.8 August release update supports additional kernels.

Release details

Install these kernels as a fresh installation or upgrade from Trellix ENS for Linux 10.7.x.

Release package: McAfeeESP-KernelModule-10.7.22-6735-Release-ePO.zip

If you have

You must

Trellix ENS for Linux 10.7.5 or later deployed on your managed systems

Update Trellix ENS for Linux 26.8 with the McAfeeESP-KernelModule-10.7.22-6735-Release-ePO kernel package to ePO - On-prem.

Trellix ENS for Linux 10.7.5 or later checked in to Trellix ePolicy Orchestrator - On-prem

Update McAfeeESP-KernelModule-10.7.22-6735-Release-ePO kernel package from ePO - On-prem.

If Trellix ENS for Linux 10.7.5 or earlier versions is checked in and deployed on managed systems

Check in and install Trellix ENS for Linux 26.8 with the McAfeeESP-KernelModule-10.7.22-6735-Release-ePO kernel package on ePO - On-prem.

New Linux distribution support

This release adds support for openSUSE Leap 16.0 for both Threat Prevention and Firewall modules.

Supported additional kernel versions

This release supports these additional kernels:

  • Debian 12

    • 6.1.0-52-amd64

  • Oracle 8

    • 5.15.0-322.203.3.2.el8uek.x86_64

    • 5.15.0-322.203.3.3.el8uek.x86_64

    • 5.15.0-322.203.3.4.el8uek.x86_64

  • Ubuntu 22.04

    • 6.8.0-136-generic

    • 5.15.0-187-generic

  • Ubuntu 20.04

    • 5.4.0-233-generic

  • Ubuntu 18.04

    • 5.4.0-233-generic

  • Ubuntu 24.04

    • 6.17.0-42-generic

    • 7.0.0-28-generic

    • 6.17.0-1021-azure

  • Debian 11

    • 5.10.0-46-amd64

  • openSuse Leap 16.0

    • 6.12.0-160000.5-default

  • Ubuntu 26.04

    • 7.0.0-22-generic

    • 7.0.0-27-generic

    • 7.0.0-28-generic

    • 7.0.0-29-generic

Additional Information

Upgrade from Trellix Endpoint Security (ENS) for Linux 10.7.5 or earlier versions

Upgrade to Trellix ENS for Linux 26.x with Trellix ENS for Linux 26.x Kernel Modules for Linux kernel package from Trellix ENS for Linux 10.7.5 or earlier versions.

Before installing or upgrading:

  • Make sure to update the Msgbus Cert Updater package to the latest available version.

  • The Msgbus Cert Updater package is available on Software Catalog under the Trellix Agent.

Download Trellix ENS for Linux 26.x Kernel Modules for Linux from Software Catalog in the same branch as McAfeeTP-<version number>-<build number>-Release-ePO.

Note

Make sure that you select the version number 10.7.5 or later.

A message displays for overwriting the package. Click OK to check in the package.

  1. Log on to the ePO - On-prem server as an administrator.

  2. Select MenuSystemsSystem Tree, then select a group or systems.

  3. On the Assigned Client Tasks tab, click Actions, then click New Client Task Assignment.

  4. Complete these options, then click Create New Task:

    1. For product, select Trellix Agent.

    2. For task type, select Product Deployment.

  5. On the Client Task Catalog page:

    1. Enter a task name.

    2. Select Linux as the target platform.

    3. In Products and components, select the product, select Install as the action, then click Save.

  6. Select the Schedule type as Run immediately and click on Save. The new task appears under the tasks list.

  7. Select the machines where the update has to run. Click on Wake Up Agents. Wait for the task to get completed. You can verify the kernel versions on the managed systems using the command lsmod.

Check in Trellix Endpoint Security (ENS) for Linux 26.x kernel package

Check in Trellix ENS for Linux with 26.x with the McAfeeESP-KernelModule-<version>-<build number>-Release-ePO kernal package.

Make sure you check in McAfeeESP-KernelModule-<version>-<build number>-Release-ePO package to Trellix ePO - On-prem in the same branch as McAfeeESP-<version number>-<build number>- package.

Note

Make sure that you select the version number 10.7.5 or later.

A message displays for overwriting the package. Click OK to check in the package.

  1. Download the .zip file from the Trellix download site to a temporary location on the Trellix ePO - On-prem server.

  2. Log on to the Trellix ePO - On-prem server as an administrator.

  3. Select Select MenuSystemsMain RepositoryCheck In Package..

  4. For Package type, select Product or Update (.ZIP).

  5. Click Choose File, select McAfeeESP-KernelModule-<version>-<build number> , click Choose, then click Next.

  6. Click Choose File, select McAfeeTP-<version>-<build number>-Release-ePO.zip , click Choose, then click Next.

  7. Select Current as the branch.

  8. Click Save.

You can verify the kernel versions on the managed systems using the command lsmod.

Update Trellix Endpoint Security (ENS) for Linux with latest kernel packages

Update Trellix ENS for Linux 26.x with Trellix Endpoint Security (ENS) 26.x Kernel Modules for Linux kernel package.

  • You must download Trellix ENS for Linux for Threat Prevention 10.7.5 or later from Software Catalog.

  • Make sure you download Trellix ENS for Linux 26.x Kernel Modules from Software Catalog in the same branch as McAfeeTP-<version>-<build number>-Release-ePO .

Note

Make sure that you select the version number 10.7.5 or later.

A message displays for overwriting the package. Click OK to check in the package.

  1. Log on to the Trellix ePO - On-prem server as an administrator.

  2. Select MenuSystemsSystem Tree, then select a group or systems.

  3. On the Assigned Client Tasks tab, click Actions, then click New Client Task Assignment.

  4. Complete these options, then click Create New Task:

    1. For product, select Trellix Agent.

    2. For task type, select Product Update.

  5. Enter the Task name and check in Trellix Endpoint Security (ENS) Kernel Modules for Linux 10.7.22 under package types. Uncheck all other boxes and click Save.

  6. Select the Schedule type as Run immediately and click on Save. The new task appears under the tasks list.

  7. Select the machines where the update has to run. Click on Wake Up Agents. Wait for the task to get completed.

You can verify the kernel versions on the managed systems using the command lsmod.

Upgrade standalone rpm machines with the latest kernel package

Upgrade your RPM systems with the McAfeeESP-<version number>-<build number>--Release-ePO kernel package using command line.

You must have Trellix ENS for Linux Threat Prevention 10.7.5 or later installed and running on your system.

  1. Copy McAfeeESP-<version number>-<build number>--Release-ePO on to your machine.

  2. Unzip the package: unzip McAfeeESP-<version number>-<build number>--Release-ePO -d kernel_module .

  3. Run these commands to upgrade the kernel module.

    For version 10.7.17 or earlier

    cd kernel_module
    mkdir aac_fileaccess
    tar -zxvf McAfeeESP-KernelModule-10.7.22-<build number>-Full.linux.tar.gz -C aac_fileaccess
    mkdir /tmp/ens_pkg/
    mkdir /tmp/ens_pkg/install/
    cd aac_fileaccess
    cp McAfeeESPAac-10.7.22-<build number>.x86_64.rpm McAfeeESPFileAccess-10.7.22-<build number>
    .x86_64.rpm /tmp/ens_pkg/install/
    yum -y --nogpgcheck --noplugins --disablerepo=* install /tmp/ens_pkg/install/*.rpm    
    /opt/McAfee/ens/tp/init/mfetpd-control.sh stop
    /opt/McAfee/ens/tp/init/mfetpd-control.sh start
    lsmod | grep mfe --> shows 100706<build number> version of kernel module
    rpm -qa | grep -i mcafee --> shows aac and fileaccess version 10.7.22.<build number>

    For version 10.7.18 or later

    cd kernel_module
    ./update-esp-kernelmodule.sh
    lsmod | grep -i mfe
    rpm -qa | grep -i mcafee --> shows aac and fileaccess version 10.7.22.<build number>

Upgrade Debian machines with the latest kernel package

Upgrade your Debian systems the McAfeeESP-<version number>-<build number>--Release-ePO kernel package using command line.

You must have Trellix ENS for Linux Threat Prevention 10.7.5 or later installed and running on your system.

  1. Copy McAfeeESP-<version number>-<build number>--Release-ePO on to your machine.

  2. Unzip the package: unzip McAfeeESP-<version number>-<build number>--Release-ePO -d kernel_module .

  3. Run these commands to upgrade the kernel module.

    For version 10.7.17 or earlier

    cd kernel_module
    mkdir aac_fileaccess
    tar -zxvf McAfeeESP-KernelModule-10.7.22-<build number>-Full.linux.tar.gz -C aac_fileaccess
    cd aac_fileaccess
    dpkg --install McAfeeESPAac-10.7.22-<build number>.deb
    dpkg --install McAfeeESPFileAccess-10.7.22-<build number>.deb
    /opt/McAfee/ens/tp/init/mfetpd-control.sh stop
    /opt/McAfee/ens/tp/init/mfetpd-control.sh start
    lsmod | grep -i mfe --> shows 100706<build number> version 
    dpkg-query -l | grep -i mcafee --> shows aac and fileaccess version -> 10.7.22-<build number>

    For version 10.7.18 or later

    cd kernel_module
    ./update-esp-kernelmodule.sh
    lsmod | grep -i mfed
    pkg-query -l | grep -i mcafee --> shows aac and fileaccess version -> 10.7.22-<build number>

Known issues

For a list of current known issues in Threat Prevention, see Trellix Knowledge Base article KB87518.

For a list of current known issues in Firewall, see Trellix Knowledge Base article KB91327.