I have to imagine that this bug has existed for quite some time and I’d be curious to know what other input validation errors they have, considering the amount of untrusted input they evaluate at ring 0 originating from userland.
At the very least, big money security software companies should be parsing untrusted content with some kind of rigorouly safe approach, not just squirting it through a big pile of C/C++.
And don't get me started on the whole concept of undefined behavior in those languages. To quote I. I. Rabi, "Who ordered that?"
the malformed files were updates from crowdstrike itself. It's not exactly "untrusted content".
[1] https://devblogs.microsoft.com/oldnewthing/20220907-00/?p=10...
I'd love to hear from an engineer on the project but unfortunately we're likely not to.
But I am in full agreement with you that sloppy programmers cannot truly be helped. They just screw up and move on like nothing happened. Sigh.
Something of this nature would have had our entire team fired. The number of phases and the thoroughness and exhaustiveness of the protocols we have to ensure we don't push bad builds would have most engineers taken aback... but we have to. With great power comes great responsibility.
BTW, using your metaphor, until 2 days ago they didn't even know that there was a fire in the basement, nor a basement.