Xorte logo

News Markets Groups

USA | Europe | Asia | World| Stocks | Commodities



Add a new RSS channel

 
 


Keywords

2024-07-24 14:00:57| Engadget

CrowdStrike has blamed faulty testing software for a buggy update that crashed 8.5 million Windows machines around the world, it wrote in an post incident review (PIR). "Due to a bug in the Content Validator, one of the two [updates] passed validation despite containing problematic data," the company said. It promised a series of new measures to avoid a repeat of the problem. The massive BSOD (blue screen of death) outage impacted multiple companies worldwide including airlines, broadcasters, the London Stock Exchange and many others. The problem forced Windows machines into a boot loop, with technicians requiring local access to machines to recover (Apple and Linux machines weren't affected). Many companies, like Delta Airlines, are still recovering.  To prevent DDoS and other types of attacks, CrowdStrike has a tool called the Falcon Sensor. It ships with content that functions at the kernel level (called Sensor Content) that uses a "Template Type" to define how it defends against threats. If something new comes along, it ships "Rapid Response Content" in the form of "Template Instances." A Template Type for a new sensor was released on March 5, 2024 and performed as expected. However, on July 19, two new Template Instances were released and one (just 40KB in size) passed validation despite having "problematic data," CrowdStrike said. "When received by the sensor and loaded into the Content Interpreter, [this] resulted in an out-of-bounds memory read triggering an exception. This unexpected exception could not be gracefully handled, resulting in a Windows operating system crash (BSOD)." To prevent a repeat of the incident, CrowdStrike promised to take several measures. First is more thorough testing of Rapid Response content, including local developer testing, content update and rollback testing, stress testing, stability testing and more. It's also adding validation checks and enhancing error handing. Furthermore, the company will start using a staggered deployment strategy for Rapid Response Content to avoid a repeat of the global outage. It'll also provide customers greater control over the delivery of such content and provide release notes for updates.  However, some analysts and engineers think the company should have put such measures in place from the get-go. "CrowdStrike must have been aware that these updates are interpreted by the drivers and could lead to problems," engineer Florian Roth posted on X. "They should have implemented a staggered deployment strategy for Rapid Response Content from the start."This article originally appeared on Engadget at https://www.engadget.com/crowdstrike-blames-bug-that-caused-worldwide-outage-on-faulty-testing-software-120057494.html?src=rss


Category: Marketing and Advertising

 

Latest from this category

07.09Theres a Stranger Things Polly Pocket set, and its design is really clever
07.09Over 1.4 million Ram 1500 trucks recalled to fix a bug in the anti-lock brake system
07.09Meta shares how WhatsApp and Messenger will interact with other messaging apps in the EU
07.09How to use a VPN on Roku
07.09Boeing's Starliner is back without the astronauts it flew to the ISS
07.09An Apple Store in Oklahoma City is close to approving an union agreement for its workers
06.09YouTubers built a six foot tall working replica of Apples iPhone 15 Pro Max
06.09YouTube terminates five right-wing channels linked to the DOJs Russia indictments
Marketing and Advertising »

All news

08.09Today's Headlines
08.09Chinese giant Chery could build cars in UK
07.09Theres a Stranger Things Polly Pocket set, and its design is really clever
07.09Over 1.4 million Ram 1500 trucks recalled to fix a bug in the anti-lock brake system
07.09Contaminated eggs sold in Illinois recalled after causing Salmonella infections
07.09Meta shares how WhatsApp and Messenger will interact with other messaging apps in the EU
07.09Body Shop's remaining stores rescued from administration
07.09How to use a VPN on Roku
More »
Privacy policy . Copyright . Contact form .