CB Defense: Kernel Panic on macOS 10.15.1 with 3.3.3.35 Sensor
search cancel

CB Defense: Kernel Panic on macOS 10.15.1 with 3.3.3.35 Sensor

book

Article ID: 291867

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense)

Issue/Introduction

  • Kernel Panic (KP) at boot time
  • KP file generated (*.panic)
    /Library/Logs/DiagnosticReports
  • Putting Sensor in Bypass has no impact (on further testing)

Environment

  • CB Defense PSC Sensor: 3.3.3.35
  • Apple macOS: 10.15.1 (Catalina)

Cause

https://community.carbonblack.com/t5/Carbon-Black-Cloud-Discussions/Kernel-Panics-on-macOS-10-15-1-when-the-Carbon-Black-Cloud/m-p/81790#M250
  • Under investigation in concert with AppleCare Support
  • Apple Enterprise team encourages Mac Enterprise customers to open an AppleCare Support case immediately
    Carbon Black/Apple Feedback #: FB7418712

Resolution

This issue is fixed with the 3.3.4.6 Sensor and higher, as well as with macOS 10.5.2 and higher.

Temporary Workaround
  1. Boot the endpoint to the Recovery Partition (or to Internet Recovery if a local Recovery Partition is unavailable) by holding Command + R
  2. Use Disk Utility to mount System volume if not yet mounted
  3. Close Disk Utility and launch Terminal, then type out the following command
    rm -rf /Volumes/<VOLUME_NAME>/Library/Extensions/CbDefenseSensor.kext
  4. Reboot endpoint to its boot partition