Article Details
Scrape Timestamp (UTC): 2024-07-21 23:54:24.801
Source: https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/
Original Article Text
Click to Toggle View
CrowdStrike's Falcon Sensor also linked to Linux kernel panics and crashes. Rapid restore tool being tested as Microsoft estimates 8.5 million machines went down. CrowdStrike's now-infamous Falcon Sensor software, which last week led to widespread outages of Windows-powered computers, has also caused crashes of Linux machines. Red Hat in June warned its customers of a problem it described as "Kernel panic observed after booting 5.14.0-427.13.1.el9_4.x86_64 by falcon-sensor process" that impacted some users of Red Hat Enterprise Linux 9.4 after (as the warning suggests) booting on kernel version 5.14.0-427.13.1.el9_4.x86_64. A second issue titled "System crashed at cshook_network_ops_inet6_sockraw_release+0x171a9" advised users "for assistance with troubleshooting potential issues with the falcon_lsm_serviceable kernel module provided from the CrowdStrike Falcon Sensor/Agent security software suite." Red Hat also advised that "disabling the CrowdStrike Falcon Sensor/Agent software suite … will mitigate the crashes and provide temporary stability to the system in question while the issue is investigated." The issue was "Observed but not limited to release 6 and 7." Linux Kernel panics and Windows Blue Screens of Death are broadly comparable. The occurrence of kernel panics mere weeks before CrowdStrike broke many Windows implementations therefore hints at wider issues at the security vendor. The Register has asked CrowdStrike to comment on the issues identified by Red Hat, and will update this story if we receive substantial information. CrowdStrike's CEO oversaw very similar McAfee meltdown In 2010, PCs around the world crashed after antivirus vendor McAfee pushed a bad update that left PCs in an endless reboot cycle. At the time, McAfee's chief technology officer was George Kurtz – who now serves as CEO of CrowdStrike. Mr Kurtz therefore has the possibly unique and almost-certainly-unwanted distinction of having presided over two major global outage events caused by bad software updates. Rapid restore tool on the way CrowdStrike on Sunday teased a rapid recovery tool for the mess it made. "Together with customers, we tested a new technique to accelerate impacted system remediation," the security vendor stated on LinkedIn, adding "We're in the process of operationalizing an opt-in to this technique. We're making progress by the minute." That progress will likely be of great interest, as Microsoft veep for enterprise and OS security David Weston on Saturday estimated that 8.5 million Windows machines had been laid low by the problem. Microsoft also created a repair tool that runs from a bootable USB storage device and can be found here, along with instructions for use. Those instructions were modified on Sunday to require a full wipe of the USB device "so it doesn't error out when used in the recovery process." CrowdStrike published technical details of the incident. It has also offered guidance on how to recover Windows machines encrypted with BitLocker. Up in the air The extent of disruption caused by CrowdStrike remains uncertain, but we've read accounts of over 6,800 flights cancelled last Friday alone, and of some airlines only restoring systems on Sunday evening. The British Medical Association has warned that "normal service cannot be resumed immediately" due to the backlog caused by the outage. Australia's home affairs minister Claire O'Neill has warned that remediation could take weeks. This remains a developing story: The Register will update this item, or write others, as further info emerges.
Daily Brief Summary
CrowdStrike's Falcon Sensor software, originally linked to crashes on Windows PCs, has also caused Linux kernel panics.
Issues arose after updates, including kernel panics on Red Hat Enterprise Linux 9.4 run systems, damaging global computer systems.
Red Hat advised disabling the Falcon Sensor to stabilize systems while investigating the software-related crashes.
The software problems recall a similar incident from 2010 involving McAfee (with the same executive, George Kurtz, involved).
CrowdStrike is developing a rapid recovery tool to address these crashes, with insights from recent tests promising faster system remediation.
Microsoft's estimate shows that approximately 8.5 million Windows machines were affected, and a specific USB-bootable recovery tool has been deployed.
The impact extended to critical services, with the British Medical Association and airlines experiencing major disruptions, indicating ongoing recovery challenges.
This story remains active and developments are expected as both CrowdStrike and external entities work on mitigating the damage and investigating the root causes.