In this instance, Falcon expected the update to have 20 input fields, but it had 21 input fields.
This "count mismatch" is what caused the global crash, CrowdStrike said.
"The Content Interpreter expected only 20 values," the RCA report states.
"Therefore, the attempt to access the 21st value produced an out-of-bounds memory read beyond the end of the input data array and resulted in a system crash."
--
https://www.abc.net.au/news/2024-08-07/drt-crowdstrike-root-cause-analysis/104193866
🤣
#falcon #Crowdstrike #rootcauseanalysis #outofbounds