Linux

Supported Linux operating systems

The following Linux operating systems support the Cortex XDR agent.

The Cortex XDR agent protects Linux servers, there are two methods for agent protection; a Kernel module and a user-mode (eBPF-based) approach. To help you choose the best deployment for your environment, see the feature differences between these two modes in the latest Cortex XDR agent Admin guide Broken link.

For the latest Kernel modules support see here.

Note

Cortex XDR agent 9.1 was the last agent release supporting Linux kernels below 3.10. To avoid service disruption, hosts running kernels below 3.10 must not be upgraded beyond the 9.1 agent line. Disable auto-upgrades for endpoint profiles managing those machines, and prevent manual upgrades of the hosts to agent versions later than 9.1

Alibaba Cloud Linux

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
Alibaba Cloud Linux 3

AlmaLinux

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
AlmaLinux 10
AlmaLinux 9
AlmaLinux 8

Amazon Linux/Amazon Linux 2/Amazon Linux 2023

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
AMI 2018.03
Amazon Linux 2 AMI
Amazon Linux 2 AMI (aarch64)
Amazon Linux 2023
Amazon Linux 2023 (aarch64)

Debian

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
Debian 13 (Trixie)
Debian 12 (Bookworm)
Debian 11 (Bullseye)
Debian 10 (Buster)
Debian 10 (Buster) aarch64
Debian 9 (Stretch)

CentOS

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
CentOS Stream 9
CentOS Stream 8
CentOS Stream 8 aarch64
CentOS 8
CentOS 8 aarch64
CentOS 7.9 aarch64

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

CentOS 7
CentOS 6
(6.7 and above)
Async mode onlyAsync mode only

Fedora Server

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
Fedora Server (USM only)

openSUSE

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
openSUSE Leap 16.0 (UM only) <p>✓</p><p>From content release 2280-36261</p> <p>✓</p><p>From content release 2280-36261</p>
openSUSE Leap 15.6 (UM only) <p>✓</p><p>From content release 2160-30885</p> <p>✓</p><p>From content release 2160-30885</p> <p>✓</p><p>From content release 2160-30885</p> <p>✓</p><p>From content release 2160-30885</p>
openSUSE Leap 15.3
openSUSE Leap 15.2
openSUSE Leap 15.1

Oracle Linux

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
Oracle 10 x86_64

From content release 1940-22526

Oracle 10 aarch64

From content release 1940-22526

Oracle 9 x86_64 — Release 9.4 and later
Oracle 9 x86_64 — Release 9.3*
Oracle 9 aarch64
Oracle 8
Oracle 8 aarch64
Oracle 7


Oracle Linux 6 (6.7 and above)

  • RHCK (kernel 2.6.32)
  • UEK Release 2 (kernel 2.6.39)
  • UEK Release 3 (kernel 3.8.13)
Async mode onlyAsync mode only

*Oracle Linux 9.3 x86_64 notes:

Kernel Support Minimum agent version
RHCK User mode only 8.2
UEK Supported 7.9-CE

Red Hat Enterprise Linux

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
RHEL 10 x86_64
RHEL 10 aarch64
RHEL 9* x86_64
RHEL 9* aarch64
RHEL 8 x86_64
RHEL 8 aarch64

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

User mode agent not supported

RHEL 7
RHEL 6 (supports 6.7 and above)Async mode onlyAsync mode only

*RHEL 9 requirement

RHEL 9.3 and later requires Cortex XDR agent version 8.2 or later.

Rocky Linux

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
Rocky Linux 10 x86_64
Rocky Linux 9 x86_64
Rocky Linux 9 aarch64
Rocky Linux 8 x86_64

SUSE Linux Enterprise Server

  Cortex XDR agent          
  9.3 9.2 9.1-CE 9.1 9.0 8.7-CE
Server 16.0 <p>✓</p><p>From content release 2280-36261</p> <p>✓</p><p>From content release 2280-36261</p>
Server 15 SP7 <p>✓</p><p>From content release 1940-22526</p>
Server 15 SP0-SP6
Server 12 SP4-SP5
Server 11 SP4 Async mode only Async mode only

Ubuntu

Cortex XDR agent
9.39.29.1-CE9.19.08.7-CE
26.04 LTS x86_64
26.04 LTS aarch64
24.04 LTS x86_64
24.04 LTS aarch64
22.04 LTS x86_64
22.04 LTS aarch64
20.04 LTS
20.04 LTS aarch64
18.04 LTS
18.04 LTS aarch64
16.04 LTS
14.04 LTSAsync mode onlyAsync mode only
12.04 LTSAsync mode onlyAsync mode only