CrowdStrike outage explained: 21 fields, 20 slots, 8.5M blue screens
The CrowdStrike outage of July 19, 2024 is the biggest IT failure most of us have lived through, and its root cause fits in one sentence: a detection template declared 21 input fields, and the code that fed it supplied 20. CrowdStrike pushed a content update that used the 21st field to every online Windows machine running its Falcon sensor, and about 8.5 million devices blue-screened and…
On July 19, 2024, CrowdStrike experienced a massive IT failure that affected about 8.5 million Windows devices worldwide. The root cause of the outage was a single line of code inside a detection template. The template declared 21 input fields, but the code that fed it supplied only 20. When CrowdStrike pushed a content update to every online Windows machine running its Falcon sensor, the mismatch led to an out-of-bounds memory read inside the kernel driver, causing the machines to blue-screen and boot-loop.
The update, labeled Channel File 291, went out at 04:09 UTC and was reverted 78 minutes later. The fix required rebooting machines in Safe Mode, and about 99% of sensors were back online by July 29. The incident caused significant disruptions, including the cancellation of around 7,000 flights and an estimated $500 million in damages.
CrowdStrike's root cause analysis highlighted the need for staged deployment of template instances and improved testing procedures.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.