Issues Resolved

This hotfix resolves the following issues:
  • The Forcepoint Email Security anti-virus scanning engine (ants_server) crashed repeatedly due to a corrupt Trellix incremental database update, causing messages to be routed to the antivirus exception queue. (EI-42713)
  • Migration between two Forcepoint Email Security v8.5.7 appliances (Azure-to-Azure and on-premises-to-on-premises) failed.
  • The "archive queue has exceeded its size limit" alert was reported in the Forcepoint Security Manager even when sufficient archive storage was available. The archive queue size counter overflowed for archive queues larger than 2 TB. (EI-41098)
  • Some messages were quarantined into the exception queue with no reason and could not be released or reprocessed, because the message file was copied from the wrong stream position and produced a 0-byte copy. (EI-41125)
  • In hybrid deployments, a message rejected at the DATA stage by the True-Source-IP SPF or relay-authentication check was still committed and delivered with an empty body, and the same message was logged as both rejected and delivered. (EI-42589, EI-42788)
  • Recipient names were truncated in the policy logs, which caused the Log Server to reject the records with "empty receiver address" and left messages in the "Waiting for message analysis" state. (EI-41901)
  • The filter crashed (KeyView assertion) when processing large calendar (.ics) attachments, including .ics files extracted from archives, which sent affected messages to the exception/abort queue. (EI-40520)
  • SPF was not evaluated for the second and subsequent messages sent on the same SMTP connection. As a result, no SPF tag reached the cleanup stage, DMARC treated SPF as None, and a prior SPF failure could keep rejecting later messages on that connection. (ESG-17714)
  • The Policy Engine used an outdated version that did not include the latest OCR scan efficacy improvements.
Note: Hotfix 01 is a standalone hotfix that includes a fix for the Policy Engine upgrade to version 10.4.