Malcolm v5.2.8
Malcolm v5.2.8 is a release to patch a major security vulnerability in OpenSSL.
-
Version bumps
- Arkime to v3.4.1
- Spicy to v1.4.0
- Update all docker images' system packages to get latest security updates, including updating OpenSSL to fix CVE-2022-0778
- CVE-2022-0778 can already be detected in network traffic by Malcolm by 0xxon/cve-2020-0601
-
Minor improvements
- Include
gvfs-backends
package in ISO-installed environments to allow mounting SMB shares in the Thunar GUI
- Include
-
Bug fixes
- Fix an issue with "read-only mode" combined with "no SSL mode" (very unlikely to have affected anybody)
- Tweak Logstash pipeline size to make it a little more conservative to avoid Logstash restarts due to running out of heap resources
Malcolm and Hedgehog Linux may be obtained by pulling or building the Docker images and/or building the ISO installer images as described in the documentation. Unofficial ISO installer images for Malcolm and Hedgehog Linux are not hosted on GitHub, but may be downloaded from https://malcolm.fyi/download/.