CrowdStrike outage: We just got more info on what, exactly, caused the chaos

CrowdStrike released a new report.
By Tim Marcin  on 
crowstrike logo over orange background
We've got new details on the CrowdStrike outages. Credit: Karl-Josef Hildenbrand/picture alliance via Getty Images

CrowdStrike has released further details Wednesday on the software issue that caused mass outages while taking down 8.5 million Windows machines. 

The company posted a post incident review (PIR) on its website detailing the problem and outlined steps on how it can improve moving forward. You can read through the entire PIR, but it's not particularly intended for casual readers — it's primarily for the technical folks.

So what happened, exactly?

The TL;DR is that CrowdStrike sent out Rapid Response Content — an update designed to respond to the changing threat landscape — but there was a bug in its Content Validator. Despite this, the update, which contained the problematic content data, rolled out to customers. The issue “resulted in an out-of-bounds memory read” which, in turn, led to Windows crashing (i.e., showing the dreaded Blue Screen of Death).

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By signing up you agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

Because so many companies used CrowdStrike, the miniscule error ended up being a massive issue. It was a small 40KB file that caused the problem, the Verge noted. That little mistake had the airline, healthcare, and banking industries out of commission. 

How does the PIR detail plans to prevent such issues in the future? It will increase testing for Rapid Response Content, add new checks for the Content Validator, and change the way it rolls out Rapid Response Content.

Topics Cybersecurity

close-up of man's face
Tim Marcin

Tim Marcin is an Associate Editor on the culture team at Mashable, where he mostly digs into the weird parts of the internet. You'll also see some coverage of memes, tech, sports, and the occasional hot take. You can find him posting endlessly about Buffalo wings on the website formerly known as Twitter at @timmarcin.


Recommended For You

Delta refused to refund passengers for CrowdStrike fiasco, so it got hit with a class-action lawsuit
"Need Help?" sign at Delta Airlines check-in counter at airport

CrowdStrike accepts Pwnie Award for Most Epic Fail in person
The CrowdStrike logo on phone screen is displayed in front of CrowdStrike logo on laptop screen.

What caused the Verizon outage yesterday? What we know.
A sign is posted on the exterior of a Verizon store on September 30, 2024 in Daly City, California

New macOS Sequoia update reportedly not playing nice with VPNs and cybersecurity tools like CrowdStrike
Apple MacBook

Trending on Mashable
Wordle today: Answer, hints for October 31
a phone displaying Wordle

NYT Connections hints today: Clues, answers for October 31
A phone displaying the New York Times game 'Connections.'

Wordle today: Answer, hints for October 30
a phone displaying Wordle

NYT Connections hints today: Clues, answers for October 30
A phone displaying the New York Times game 'Connections.'

The biggest stories of the day delivered to your inbox.
This newsletter may contain advertising, deals, or affiliate links. Subscribing to a newsletter indicates your consent to our Terms of Use and Privacy Policy. You may unsubscribe from the newsletters at any time.
Thanks for signing up. See you at your inbox!