This is a point release.
(Same as Whonix VirtualBox 15.0.0.4.9 - Release Candidate - Testers Wanted!)
Download:
Alternatively, in-place release upgrade is possible.
Notable Changes:
-
Mostly same as Whonix VirtualBox 15.0.0.3.9 - Testers Wanted! - Stronger Linux User Account Isolation and more Hardening but change default umask removed and replaced with better solution permission lockdown (linux pam based).
-
tb-starter bug fixed.
-
Upgraded Hardened Malloc to version
2
and switched to compile with clang rather than gcc as per upstream preference. -
msgcollector mount option hardening
-
Bluetooth is blacklisted to reduce attack surface.
-
Requires every module to be signed before being loaded. Any module that isunsigned or signed with an invalid key cannot be loaded. This makes it harder to load a malicious module.
-
Abort login for users with locked passwords [security-misc]
-
informational output during Linux PAM [security-misc]
- Show failed and remaining password attempts.
to read and write to newly created files. - Document unlock procedure if Linux user account got locked.
- Point out, that there is no password feedback for
su
. - Explain locked (root) account if locked.
- Show failed and remaining password attempts.
-
remove system.map after kernel upgarde
-
abort login without asking for password if it will fail anyhow
Full difference of all changes:
https://github.com/Whonix/Whonix/compare/15.0.0.3.9-developers-only...15.0.0.4.9-developers-only
This release would not have been possible without the numerous supporters of Whonix!
Please Donate!