- 04:09 UTC · Channel File 291 · 21 fields into a driver built for 20 · 8.5 M blue screens
- the fix is manual: Safe Mode, delete C-00000291*.sys, BitLocker key · Delta: 7,000 flights, $500 M
+ 05:27 reverted · bounds check in 6 days, staged rings, customer control · git blame 65 / 25 / 10One security update carries twenty-one fields into a driver built for twenty, and eight and a half million Windows machines blue-screen before breakfast. July 19, 2024, 04:09 UTC. CrowdStrike pushes Channel File 291 to every Falcon sensor. Seventy-eight minutes later they pull it; by then airlines, hospitals and banks stare at the same blue rectangle. The CEO's first post says not a cyberattack, true, and not the point. How it happens, why it is possible, and who gets the blame.
February 28th. Sensor 7.11 ships a new detector for named pipes. It declares twenty-one input fields; the code that feeds it builds an array of twenty. Nobody notices: for four months every rule leaves field twenty-one as a wildcard, and nobody reads a wildcard. A stress test passes, four rules ship, all fine. July 19th, 04:09. Two new rules; one puts a real pattern in field twenty-one. The cloud validator counts twenty-one against the declaration and says fine. Every online Windows host downloads it at once, because there is no canary ring. The sensor reads slot twenty-one, which is not its memory, and the kernel does what kernels do. 05:27, reverted. Too late for anyone who rebooted: the driver loads early in boot, reads the same file, and crashes again. Boot loop.
Why is this possible? The rules are configuration pushed from the cloud, so not code skips the code pipeline. The interpreter has no bounds check; it trusts the validator, and the validator trusts the declaration. And it all runs in kernel mode, where a bad pointer is not an exception but a page fault Windows says cannot be protected by try-except. Patrick Wardle reads it off a crash dump that afternoon: index zero x fourteen, slot twenty-one. The fix is manual. Safe Mode, delete C-00000291, reboot. With BitLocker, first type a forty-eight-digit recovery key that lives on a server which is also blue. git blame. CrowdStrike, sixty-five percent: the RCA lists six findings, and finding six is a full sentence: Template Instances should have staged deployment. The kernel-mode design, twenty-five: CrowdStrike says Windows cannot yet host security outside the kernel, Microsoft says not a Microsoft incident, and the page fault does not care. The Friday, ten. The commit message says not code.
Blast radius: eight and a half million devices, under one percent of Windows. Delta cancels seven thousand flights and sues for five hundred million, Microsoft included. Insurers put the Fortune 500 bill near five billion. Hacker News: forty-five hundred points. The irony: an update meant to detect novel attack techniques delivered one. Verdict, postmortem: ship it, narrowly. Bounds check in six days, staged rings, customer control over content updates, two outside reviews. Narrowly, because all of that was standard practice already. Monday: whatever your agent pulls from the cloud gets a canary ring. Configuration is code the moment something parses it where it cannot throw. Send me the incident you are still not allowed to talk about, in the comments, or at the daily diff dot dev.
Verdict: SHIP IT — bounds check in 6 days · staged rings · customer control · RCA in 18 days
Sources
https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf
https://www.crowdstrike.com/wp-content/uploads/2024/08/Executive-Summary_Root-Cause-Analysis_Channel-File-291.pdf
https://www.crowdstrike.com/en-us/blog/falcon-content-update-preliminary-post-incident-report/
https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/
https://web.archive.org/web/20240719145915/https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/
https://blogs.microsoft.com/blog/2024/07/20/helping-our-customers-through-the-crowdstrike-outage/
https://www.sec.gov/Archives/edgar/data/27904/000168316824005369/delta_8k.htm
https://homeland.house.gov/wp-content/uploads/2024/09/2024-09-24-HRG-CIP-Testimony-Meyers.pdf
https://homeland.house.gov/hearing/an-outage-strikes-assessing-the-global-impact-of-crowdstrikes-faulty-software-update/
https://x.com/George_Kurtz/status/1814235001745027317
https://x.com/patrickwardle/status/1814343502886477857
https://news.ycombinator.com/item?id=41002195
https://news.ycombinator.com/item?id=41021366
https://www.theguardian.com/technology/article/2024/jul/24/crowdstrike-outage-companies-cost
https://news.ycombinator.com/item?id=41534716
https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_outages
And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.
YouTube · thedailydiff.dev · forward this to the intern who deployed on Friday.

