4 ms·
Oddly enough, there was an issue last month with CrowdStrike and RHEL 9 kernel where they were triggering a kernel panic when attempting to load a bpf program f
by broknbottle 2y ago
Oddly enough, there was an issue last month with CrowdStrike and RHEL 9 kernel where they were triggering a kernel panic when attempting to load a bpf program from their newer bpf sensor. One of the workarounds was to switch to their kernel driver mode.
This was obviously a bug in RHEL kernel because even if the bpf program was bunk it should not cause the kernel to panic. However, it's almost like CrowdStrike does zero testing of their software and looks at their end users as Test/QA.
https://access.redhat.com/solutions/7068083 https://access.redhat.com/solutions/7068083
> 4bb7ea946a37 bpf: fix precision backtracking instruction iteration
- CaliforniaKarl 2y agoThe kernel update in question was released as part of a RHEL point release (9.3 or 9.4, I forget which). I’m not sure how much early warning RH gives to folks when a kernel change comes in via a point release. Looking at https://www.redhat.com/en/blog/upcoming-improvements-red-hat-enterprise-linux-minor-release-betas https://www.redhat.com/en/blog/upcoming-improvements-red-hat..., it seems like it’s changing for 9.5. I hope CrowdStrike will be able to start testing against those beta kernels.
- broknbottle 2y agoIt was 9.4. I don’t think any amount of heads up will make a difference considering it took them like 3+ years to notice that E4S streams were a thing. Most of these security vendors tend to treat Linux as the red headed step child and do the least.. With that said, after the recent event it would seem that CrowdStrike treats all OSes as red headed step children lol https://access.redhat.com/solutions/7001909 https://access.redhat.com/solutions/7001909