Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

Carbon Black Cloud: Linux Config_IKHeaders=m shows in results but sensor stays in bypass saying Kernel Headers are needed

Carbon Black Cloud: Linux Config_IKHeaders=m shows in results but sensor stays in bypass saying Kernel Headers are needed

Environment

  • Carbon Black Cloud Linux Sensor: 2.10 and newer
  • Kernels: Linux 4.4 Kernels and newer

Symptoms

Sensor stays in bypass saying Kernel Headers are needed while checking prerequisite for Linux install command:

cat /boot/config-$(uname -r) | grep CONFIG_IKHEADERS

results show:

Config_IKHeaders=m

Cause

Specific functionality is missing or corrupt.

Resolution

Install Devel Headers or reinstall Kernel Headers using this Guide.

Additional Notes

Config_IKHeaders=m means the kernel module should be there.
If the sensor says it is in bypass because of the Kernel headers with the value Config_IKHeaders=m then they must be missing or corrupt.

Related Content


Was this article helpful? Yes No
0% helpful (0/1)
Article Information
Author:
Creation Date:
‎01-18-2023
Views:
975
Contributors