SECURITY UPDATES
Bugs have been identified that disable security services upon reboot and prevent installations on hardened RHEL systems.
Microsoft has disclosed two distinct issues affecting Microsoft Defender for Endpoint on Linux. One bug causes the security service to be disabled following a system reboot, while a separate issue prevents successful updates on Red Hat Enterprise Linux (RHEL) 8 and 9 systems running in FIPS mode.
The more critical vulnerability impacts versions 101.26042.0000 through 101.26042.0009 across all supported Linux distributions. Microsoft has noted that following an upgrade or reinstallation and a subsequent reboot, the Defender service may be disabled on certain devices.
“If you use Defender for Servers (Plan 1 or 2) with Defender for Cloud and have the MDE [Microsoft Defender Endpoint] integration enabled, automatic updates for the MDE.Linux extension are enabled by default, which means your machines could have received an affected version automatically,” Microsoft explained.
The company added, “If an affected version was installed, the issue might impact active protection on rebooted devices until remediation steps are taken.”
While Microsoft has not specified the root cause of the service deactivation, any failure in endpoint protection poses a significant risk to system administrators. Additionally, a separate problem affects RHEL 8 and 9 systems operating in FIPS mode. On these systems, the 101.26042.x update may fail to install, leaving the devices running on older versions. FIPS (Federal Information Processing Standards) dictates specific cryptographic requirements for government and highly regulated environments.
Microsoft’s release notes recommend that users affected by the service-disabling bug update to build 101.26042.0011. The installation issues involving FIPS-enabled systems are resolved in version 101.26052.0011 and subsequent releases.
Microsoft Defender for Endpoint for Linux is designed to protect on-premises and cloud-based server workloads. According to Microsoft, the platform assists in preventing, detecting, investigating, and responding to advanced threats through unified visibility via the Microsoft Defender portal.
While various endpoint security alternatives exist, organizations integrated into the Microsoft ecosystem often favor the unified management capabilities of Defender for Endpoint. However, the occurrence of updates that both disable active protection and fail to install on security-hardened systems presents a significant challenge in an environment of increasing cyber threats.

