|
|
|
|
|
by svantex
697 days ago
|
|
Right, they write rather cryptically "This is not related to null bytes contained within Channel File 291 or any other Channel File." That's not quite the same as saying "This is not related to Channel File 291 containing all nul bytes."... I don't have first to hand knowledge here, but rely on Dave Plummer's statement. Regardless of zeroes or single files or not, the fact is that bad data in C-00000291.sys in combination with bad validition in the driver causes it to crash. Deleting C-00000291.sys causes the driver to stop crashing. Anyway, my main point isn't really about this. It's about the big bang global roll out simultaneously to at least 8.5 million systems in one go that's irresponsible. The driver architecture is the lesser evil here, although it's bad enough! |
|
This is, in fact, not a fact. We really don't know yet.
CrowdStrike blue screened one of my laptops twice right as the incident was getting started, before a fix was available. There was no boot loop in my case. I was back up and in the middle of an episode of Breaking Bad the second time it got me, 30 minutes after the first. Did the agent wait that long to load a content update it had already loaded before? Maybe, but it's at least as likely that the content was loaded the whole time, and that some activity pattern set it off. Thus, I'm skeptical of the problem being simple content validation.