Skip to content

Issue in Elastic Defend's 8.17.8/8.18.3/9.0.3 Network Driver May Lead To Bug Checks #90

@gabriellandau

Description

@gabriellandau

Description

An issue in Elastic Defend's network driver may lead to kernel pool corruption, resulting in bug checks (BSODs) on Windows systems with a large number of long-lived network connections which remain inactive for 30+ minutes.

The system may bug check with any of a variety of codes such as IRQL_NOT_LESS_OR_EQUAL, SYSTEM_SERVICE_EXCEPTION, or PAGE_FAULT_IN_NONPAGED_AREA.

Affected and Fixed Versions

This regression only affects the following versions of Defend:

Affected Version Earliest Fixed Version
8.17.8 8.17.9
8.18.3 8.18.3+build202507101319 (hotfix release)
9.0.3 9.0.3+build202507110136 (hotfix release)

Mitigation

Affected users should upgrade to a fixed version listed above or later.

Customers who are unable to upgrade can set advanced.kernel.network: false in Defend advanced policy.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions