Please Read: Issues identified in Cb Response v.5.2.5/6.0.1 Windows and v.5.2.6 MacOS sensors
During the week of 2/6, we made Cb Response version 5.2.6 available via our YUM repositories and to our cloud customers. This package contained a Windows Sensor v.5.2.5 and a MacOS sensor version 5.2.6. Issues were discovered in both of these sensor versions shortly after release, and as a result, we disabled downloads of this version from our repos.
Based on download statistics, this issue appears to only affect ~25 customers who updated to 5.2.6 before we disabled the YUM link. If you updated to 5.2.6, please do not push out the included 5.2.5 Windows Sensors or 5.2.6 MacOS sensors until further notice.
*Note: If you upgraded, there is no issue with continuing to run the 5.2.6 Cb Response Server.
The Cb Response Engineering Team is working diligently to find solutions to the issues we identified. Please watch this post for updates.
We apologize for any inconvenience this may cause, please reply back to the post or contact support with any further questions.
Technical Product Manager - Cb Response
***UPDATE 2/21: Cb Response Engineers have found a temporary solution to mitigate the deadlock issue on the 5.2.5 Windows Sensor. Please go to the sensor page in your console and for each sensor group do the following: Click edit settings - > Click the Event collection tab- > Uncheck "Binary Module Loads". By disabling "Binary Module Loads" the deadlock condition should be mitigated. ***Note: Disabling "Binary Module Loads" will stop the collection of modload events from your endpoints. Depending on how your users leverage the product, this could impact detection and investigation capabilities. Once this is done, please see the post for rollback instructions. Please follow this page for further updates.
***UPDATE 2/22: The windows sensor deadlock issue also affects version 6.0.1. This sensor was only available to cloud customers and all affected customers were notified of this directly via email over the weekend. Adding the update here for completeness. -Thanks
***UPDATE 2/23: Cb Response Engineering has completed the fix for the deadlock issue identified with the 5.2.5/6.0.1 Windows sensors. We are currently in QA/Testing and validation and should be in a position to provide an estimated timeline for delivery early next week. Also, we updated the support solution here: Rollback 5.2.5 and 6.0.1 Windows Sensors. The updates cover instructions for removing the affected sensor versions from the Console UI. -Thanks
We have a new version, 5.3, of the Windows Sensor that addresses the recent issues encountered in the 5.2.5 and 6.0.1 releases. Due to the limited content in this release we will be releasing it as a hotfix release rather than a GA release. As such, it will not be made public on our Yum site and access will be made available via Carbon Black Technical Support.
The sensor is intended for the following scenarios only:
You are still running the 5.2.5 or 6.0.1 Windows sensor
There were fixes in 5.2.5 / 6.0.1 that you require
Release notes for 5.3 can be found here: to review the included fixes.
If you downgraded your windows sensors to 5.2.1 and do not need a specific fix included in 5.3 it is recommended that you remain on 5.2.1.
If you meet one of the above scenarios, please contact Technical Support for access to the hotfix. -Thanks