sk182648 - Memory leak in up_manager_create_template_msg
Memory leak in up_manager_create_template_msg
Product: Security Gateways
Version: R81 (EOS), R81.10 (EOS), R81.20, R82
Last Modified: 2025-02-25
Symptoms
- The "fw ctl zdebug drop" command and the fwk.elg file show:
up_manager_create_template_msg: failed to create kbuf
up_set_srv_proto_matched_rulenums_cache: failed to allocate matched_rules_kbuf_id;
up_manager_create_template_msg: failed to create kbuf
up_fw_set_cphwd_template: up_manager_create_template_msg failed;
up_manager_fw_handle_first_packet: up_fw_do_rulebase_accept_action failed
fwhandle_pool_add: Table kbufs - All available pools exhausted
```
- Memory leak detection ([sk35496](https://support.checkpoint.com/results/sk/sk35496)) shows:
```
leak_report: 588 bytes allocated in thread id 0 leaked at 0x7fd21e604300 at time 66603807 called by: up_manager_create_template_msg
```
- High memory usage seen in "fw ctl pstat" (~60%)
- Affected versions:
Starting from:
- R81 Jumbo Hotfix Accumulator Take 99
- R81.10 Jumbo Hotfix Accumulator Take 141
- R81.20 Jumbo Hotfix Accumulator Take 70
## Cause
Memory leak happens when using dynamic object in the Rule Base (such as Domain, IDA access role, updatable objects) and a template is offloaded to the SecureXL device.
The original fix PRHF-31146 does not address certain scenarios of the issue. As a result, it affects memory usage and the Security Gateway performance.
## Solution
This problem was fixed. The fix is included in:
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 10
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 89
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/R81.10/R81.10-List-of-all-Resolved-Issues.htm?tocpath=_____4) starting from Take 169
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 106
If you choose not to upgrade, Check Point can supply a **Hotfix**.
[Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.
**Hotfix installation instructions:**
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).
## Article Properties
**Access Level**: General
**Status**: Approved
**Date Created**: 2024-09-03
**Last Modified**: 2025-02-25