IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.

Release Notes Tanium Client (Version 7.9.3.5139)

From Tanium Knowledge Base
Jump to navigation Jump to search

This Release Notes document lists changes to the Tanium Client v7.9.3.5139. The release notes for the previous Tanium Client version can be found here: Release Notes Tanium Client (Version 7.8.4.1333).

Tanium Client 7.9.3.5139

  • Tanium Cloud availability: 2026-09-08.
  • On-premises availability: 2026-09-08.


Special Notes

  • This release of the Windows Tanium Client is now a 64-bit binary on 64-bit Windows machines. 32-bit Windows installs will continue to install the 32-bit Tanium Client.
  • This release of the Tanium Client requires a change to host-based security exclusions on Windows machines.
  • For additional details on the 7.9.3 Tanium Client, see this page.
  • Updated the End User License Agreement (EULA) presented by the Tanium Server, Client, Module Server, and Zone Server installers to the August 2026 version.

Security Updates

  • None.

New Features

  • The Tanium Client logs on startup the architecture of its compiled binary and the underlying operating system, like: "Client compiled for x86 running on x86_64".
  • The Tanium Client now uses a highest random weight hashing algorithm to decide which downloaded chunks to cache, distributing chunks across peers in a neighborhood so each chunk is cached by a single peer to reduce duplicate storage and bandwidth usage.
  • Adds the Online sensor as a built-in sensor in the Tanium Client, which always returns True for extended entities.
  • A 64-bit Tanium Client now routes package action commands through a 32-bit process by default, so package content does not need to be rewritten for 64-bit compatibility.
  • The new 64-bit Tanium Client for Windows executes internal runscript packages in the 32-bit helper process for consistent behavior with legacy content.
  • Adds Crashpad crash reporting support to the Tanium Client.
  • Adds 32-bit OpenSSL and a 32-bit script runner to the 64-bit Tanium Client installer for Windows, enabling legacy 32-bit sensor and package content to execute.
  • The Tanium Client now enforces that entity computer ID namespaces are non-zero, as zero is reserved for the Tanium Client itself.
  • Adds a specific error message to cx-socket communications so the Tanium Client can signal a failed management rights evaluation without waiting for the connection to time out.
  • Adds a test computer-name diagnostic command to the Tanium Client that explains how the value returned for the Computer Name sensor is resolved on an endpoint, including the configured HostFQDN and HostDomainName overrides and each platform resolution step.
  • Adds the MacComputerNameMode setting to the Tanium Client which controls how the Computer Name sensor is resolved on macOS endpoints, accepting hostname, SCComputerName, or SCLocalHostName to avoid the frequently changing network-derived names.
  • The Tanium Client on non-Windows platforms now provides the FirstInstall and LastInstall configuration values, matching the behavior already present on Windows.

Improvements

  • Tanium Platform components now ship with OpenSSL v3.5.8.
  • Tanium Platform components now ship with Python 3.12.14.
  • The libpq PostgreSQL client library bundled with Tanium Platform components no longer initializes OpenSSL itself, avoiding a duplicate initialization that could crash the hosting process.
  • Tanium Platform components now ship with SQLite v3.53.2.
  • The Tanium Client now implements the download RPCs (CreateDownload, GetDownload, ListDownloads, DeleteDownload) of its gRPC API, letting callers manage API downloads over gRPC instead of SOAP to reduce concurrent connections.
  • Tanium Platform components now ship with v8.20 of libcurl.
  • Tanium Platform components now ship with libexpat v2.8.0.
  • Tanium Platform components now ship with xz library v5.8.3 and had removed unnecessary dependencies on it.
  • Tanium Platform components now ship with protobuf v3.25.5.
  • Removes unused module components from the Python builds distributed with Platform software components.
  • Updated the version of python-six shipped with Platform to v1.17.0.
  • Platform components now ship with pyasn1 v0.6.3.
  • Provides a single Tanium Client installer for Windows that installs the 32-bit or 64-bit client to match the architecture of the target system.
  • Increases the Tanium Client sensor child process send timeout from 10 seconds to 1 minute, reducing the frequency of "Failed to send to sensor child process" errors.
  • Adds a 32-bit helper process to the 64-bit Tanium Client for Windows to execute legacy sensor and package content that requires a 32-bit runtime.
  • The Tanium Client now deletes outbound module messages from disk that it cannot parse, decrypt, or verify when loading them from its local database, rather than failing to deliver subsequent messages.
  • The Tanium Client now includes extension isolation configuration in CX start messages, allowing CX extensions to start without performing their own configuration lookup.
  • The Tanium Client no longer duplicates sensor execution log entries in log0.txt; executions are now logged only to sensor-history0.txt when the LogSensorExecution setting is active.
  • Adds optional SHA-256 hash support to the Tanium Client download API.
  • Adds a persistent store of inbound module messages to the Tanium Client where messages are saved before being acknowledged to the Tanium Server.
  • Adds the protocol buffer definitions needed for module messaging between Tanium Servers and Tanium Clients.
  • Ensures that certificate serial numbers are non-zero and fit within a 20-byte field, in keeping with RFC 3280.
  • Tanium Platform components now ship with the boost v1.87 libraries.
  • Improves data protection on Linux systems so that the data protection key resides in the Tanium application directory rather than a user home directory, making decryption less dependent on which user account runs Tanium commands.

Bug Fixes

  • Fixed an omission in the Tanium Windows installers where the OriginalFilename version field was missing, which prevented building an AppLocker Publisher rule against them.
  • Fixed an issue in Tanium Windows binaries where the version resource did not include an OriginalFilename entry, causing AppLocker publisher rules to fail to build for signed binaries such as TaniumClient.exe and TaniumCX.exe.
  • Prevented a crash in the Tanium Client logging path when evaluating a sensor with no definition for the endpoint's platform, which previously caused group evaluation to fail and report ECF manifest errors.
  • Fixes a crash in the Tanium Client on Windows endpoints with .NET Framework 1.1 installed, where the sensor sub-process would fail to start and every sensor would return Failed to send to sensor child process: broken pipe.
  • Fixed a race condition in the Tanium Client download chunk cache where a cached file entry could be released without holding the cache lock, corrupting the internal age-list and crashing during cleanup.
  • Fixes an issue in the Tanium Client where an inter-process communication socket file might be created outside the client's installation directory.
  • Fixed an inaccuracy in the Tanium software bill of materials where the llhttp package was listed as a runtime dependency; it is now correctly marked as a build-time-only dependency and no longer flagged as vulnerable in dependency scans.
  • Fixed an issue in the Tanium Client where enqueued CDN config request messages did not trigger transmission of the queue.
  • Fixes an issue in the Tanium Client where a download database that could not be loaded would produce a repeating no such column SQL error and prevent the client from starting; the client now resets the download database when it cannot be loaded.
  • Fixes a busy loop in the Tanium Client caused by an invalid module message batch not being cleared between processing runs.
  • Fixes an omission in the Tanium Client where unicast and broadcast message sequences were not trimmed during registration.
  • Prevents Tanium Clients from publishing unicast messages to other clients or sending broadcast messages; such messages are now blocked at the client and dropped at the Tanium Server.
  • Fixes an issue where unzipping a file with malformed timestamp metadata would throw an InvalidDate error; out-of-range timestamp fields are now clamped to the expected range.
  • Fixes an issue in the Tanium Client where an invalid GetNumeric call for a mismatched integer size would throw an assertion instead of logging a non-fatal error.
  • Fixes an issue on Solaris x86 where Tanium Client mailbox messages using Protobuf bytes fields were processed incorrectly due to incorrect endianness handling.
  • Fixes an issue in the Tanium Client where connections used to retrieve bandwidth throttle information always closed after 5 seconds because the idle timer was not reset when throttle messages were received.
  • Fixes an issue in the Tanium Client test registration command where the ServerPort setting from the local client configuration was not respected, causing the command to connect using the default port.
  • Fixes an issue in the Tanium Client installer for Windows where the TaniumClient.exe inbound Windows Firewall rule was not removed during uninstallation.
  • Fixed an issue on AIX where the Tanium Client's IP Address sensor failed with an EADDRNOTAVAIL error caused by a defect in the getifaddrs compatibility shim, which queried the network interface mask using a zero address instead of the interface's own address.
  • Fixes an issue in the Tanium Client cx-socket connection handler where a reused event could cause the error "Callback is already connected to another source" to be reported.
  • Fixes an issue where a Tanium Client did not regenerate its computer ID after a Tanium Server database was reverted to an earlier snapshot, leaving the client able to register but unable to report question results and causing encrypted messages for the unknown computer ID to be dropped.
  • Fixes a busy loop in the Tanium Client where it would continuously resend entity ID requests, triggering a failed m_availableComputerIds.count == 0 assertion, when interpreting server-provided computer IDs.
  • Corrects the CPE identifier for the xz library in Tanium platform SBOMs so that the vendor reads tukaani rather than a wildcard.
  • Fixes an issue in the Tanium Client where the tanium_cx_channel_responses_bytes_sent_total metric always reported zero instead of the number of bytes sent.
  • Fixes an omission in the Tanium Client where the TANIUM_SUPPORTS_DISKLESS_MAILBOX environment variable was not set, leaving the Python diskless mailbox interface unavailable to Python sensors.
  • Fixes an issue in the Tanium Client uninstaller for Windows where uninst.exe and other files left in the application directory could be removed after a subsequent reboot.
  • Fixes an issue in the Tanium Client download API where two requests with the same path but different URLs could overwrite the same downloaded file; the API now allows only a single URL per download path.


Known Issues and Workarounds

  • None.
    Workaround: Not needed.

Product Documentation and Resources