Fortanix Data Security Manager (DSM) 5.2.2859.3360 release provides an overview of resolved issues.
This release is superseded by the April 20, 2026, release.
WARNING
If you want to upgrade Fortanix DSM to version 5.2.2859.3360, your current DSM version must be at least 4.36 patch 5*.
Downgrade from 5.2.2859.3360 to any prior version is not supported due to Kubernetes and Kernel upgrades.
*The minimum required version is specific to your current major.minor version. You must first upgrade to the required patch level within your current version before proceeding to version 5.2.2859.3360.
NOTE
The Fortanix DSM cluster upgrade must be done with Fortanix Support on call. Please reach out to Fortanix support if you are planning an upgrade.
The customer's BIOS version must be checked by Fortanix Support before the Fortanix DSM software upgrade. If required, the BIOS version should be upgraded to the latest version and verified by Fortanix Support for a smooth upgrade.
If your Fortanix DSM version is 5.0 or later, then the HSM Gateway version must also be 5.0 or later. Similarly, if the HSM Gateway version is 5.0 or later, then your Fortanix DSM version must be 5.0 or later.
1. Bug Fixes
Fixed an issue where intermittent downtime occurred during upgrade from Fortanix DSM version 5.2 to 5.4 in 3-node clusters (DC2+1) with External Load Balancer when Kubernetes (k8s) upgrades ran in parallel on two nodes located in the same data center (JIRA: RODE-345).
Fixed an issue where during upgrades to Fortanix DSM versions 5.0 or 5.2, users belonging to custom sudo groups (groups other than the system’s default administrator sudo group) could lose sudo access after upgrade (JIRA: ES-573).
Updated the
runcpackage version from1.2.5-0ubuntu1~24.04.1to1.3.3-0ubuntu1~24.04.2affecting DSM on-prem deployments running Ubuntu 24.04 to address the container escape vulnerability CVE-2025-31133 (JIRA: ES-580).
2. Known Issues
When using an external load balancer configured with HTTP-based health checks on port 4445 (for example,
GET /sys/v1/healthor/health), the endpoint returns an HTTP 404 (Not Found) response starting from DSM version 5.2 (JIRA: RODE-580).
For a complete list of new features, enhancements to existing features, other improvements, bug fixes, and known issues, refer to the full description of the DSM 5.2 release notes.
3. Installation
To install the DSM Runtime Encryption® SGX (on-prem/Azure) and Software (AWS/Azure) packages, Download Here.