Global BSOD

Associate
Joined
19 Nov 2021
Posts
996
Location
Portsmouth
Where?

And why would the updated file be full of zeros rather than the erroneous one?
From Crowdstrike (if you can believe them):

Channel File 291​

CrowdStrike has corrected the logic error by updating the content in Channel File 291. No additional changes to Channel File 291 beyond the updated logic will be deployed. Falcon is still evaluating and protecting against the abuse of named pipes.

This is not related to null bytes contained within Channel File 291 or any other Channel File.

Also here:

Some people report that the files responsible for the CrowdStrike crashes (Eg. C-00000291-00000000-00000032.sys) are full of zeroes. This is not the case for any of the machines I fixed by hand today. One example is ad492bc8b884f9c9a5ce0c96087e722a2732cdb31612e092cdbf4a9555b44362.
@virustotal
)
 
Last edited:
Caporegime
Joined
29 Jan 2008
Posts
58,934
From Crowdstrike (if you can believe them):

Channel File 291​

CrowdStrike has corrected the logic error by updating the content in Channel File 291. No additional changes to Channel File 291 beyond the updated logic will be deployed. Falcon is still evaluating and protecting against the abuse of named pipes.

This is not related to null bytes contained within Channel File 291 or any other Channel File.

Thanks, that's odd, I don't think that implies the updated file is full of zeros though rather just that the files people showed full of zeros weren't the cause of the crash - though deleting it apparently did fix it.
 
Back
Top Bottom