Carbon Black Cloud Linux Sensor reporting 'Error (Contact support)' on RHEL 9.8
search cancel

Carbon Black Cloud Linux Sensor reporting 'Error (Contact support)' on RHEL 9.8

book

Article ID: 443336

calendar_today

Updated On:

Products

Carbon Black Cloud Enterprise EDR Carbon Black Cloud Endpoint Standard

Issue/Introduction

  • The Carbon Black Cloud Linux sensor displays an "Error (Contact support)" status in the console or enter Bypass mode after an upgrade to Red Hat Enterprise Linux (RHEL) 9.8. This occurs due to a BPF probe compilation failure on specific newer kernels.
  • $ /opt/carbonblack/psc/blades/E51C4A7E-2D41-4F57-99BC-6AA907CA3B40/bpf/event_collector -p shows:
    [I] Boot : startComponents : Attempting to compile probe...
    [I] BpfProbe : PrepareProgramAndLoadProbe : Initializing BPF Program ...
    [W] libbpf: prog 'raw_syscallssys_enter': BPF program load failed: Invalid argument
    [W] libbpf: failed to load BPF skeleton 'sensor_bpf': -22

Environment

  • Carbon Black Cloud Linux Sensor 2.16.1 and 2.16.2
  • RHEL 9.7 or 9.8
  • Kernel 5.14.0-687.10.1.el9_8.x86_64

Cause

This issue is caused by a compatibility issue (CRE-24121) where the sensor's eBPF event collector fails to load the BPF probe on RHEL 9.8 kernels.

Resolution

  1. Upgrade the affected sensor(s) to version 2.16.3 or later.
  2. Verify the sensor status returns to Healthy in the console.

Additional Information

For more details on supported kernels, see Linux Operating Systems and Respective Sensors