sk182648 - Memory leak in up_manager_create_template_msg

Memory leak in up_manager_create_template_msg

Product: Security Gateways
Version: R81 (EOS), R81.10 (EOS), R81.20, R82
Last Modified: 2025-02-25

Symptoms

    up_manager_create_template_msg: failed to create kbuf
    up_set_srv_proto_matched_rulenums_cache: failed to allocate matched_rules_kbuf_id;
    up_manager_create_template_msg: failed to create kbuf
    up_fw_set_cphwd_template: up_manager_create_template_msg failed;
    up_manager_fw_handle_first_packet: up_fw_do_rulebase_accept_action failed
    fwhandle_pool_add: Table kbufs - All available pools exhausted
    ```
- Memory leak detection ([sk35496](https://support.checkpoint.com/results/sk/sk35496)) shows:
    
    ```
    leak_report: 588 bytes allocated in thread id 0 leaked at 0x7fd21e604300 at time 66603807 called by: up_manager_create_template_msg
    ``` 
- High memory usage seen in "fw ctl pstat" (~60%)  
- Affected versions:
    
    Starting from:
   
  - R81 Jumbo Hotfix Accumulator Take 99  
  - R81.10 Jumbo Hotfix Accumulator Take 141  
  - R81.20 Jumbo Hotfix Accumulator Take 70

## Cause

Memory leak happens when using dynamic object in the Rule Base (such as Domain, IDA access role, updatable objects) and a template is offloaded to the SecureXL device.

The original fix PRHF-31146 does not address certain scenarios of the issue. As a result, it affects memory usage and the Security Gateway performance.

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 10  
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 89  
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/R81.10/R81.10-List-of-all-Resolved-Issues.htm?tocpath=_____4) starting from Take 169  
- [Jumbo Hotfix Accumulator for R81](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81/Default.htm) starting from Take 106

If you choose not to upgrade, Check Point can supply a **Hotfix**.

[Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

## Article Properties  
**Access Level**: General  
**Status**: Approved  
**Date Created**: 2024-09-03  
**Last Modified**: 2025-02-25