sk183512 - Threat Extraction Software Blade may inadvertently delete some system files
Threat Extraction Software Blade may inadvertently delete some system files
Product
Threat Extraction
Version
R80.30 (EOS), R80.30SP (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82
OS
Gaia
Last Modified
2025-09-14
Symptoms
- In a rare case, during the automatic deletion of temporary files the Threat Extraction Software Blade may inadvertently delete some Gaia OS system files, which may render the Security Gateway unstable.
- This issue applies to all these Security Gateways, Clusters, Scalable Platform Security Group and VSX Virtual Systems:
- The Threat Extraction Software Blade is enabled, and the IPS Software Blade is disabled
- Versions R80.30 and higher
- All Quantum Security Gateways on all hardware platforms (including Check Point Threat Emulation appliances)
- All CloudGuard Network Security Gateways
- This issue does not apply to Quantum Spark Gateways (neither Locally Managed, nor Centrally Managed).
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for Quantum Force 3900 Appliances starting from Take 22
- Jumbo Hotfix Accumulator for R82 starting from Take 25
- Jumbo Hotfix Accumulator for R81.20 starting from Take 103
- Jumbo Hotfix Accumulator for R81.10 starting from Take 177
If you choose not to upgrade, there are two possible options:
Option 1 (Recommended) - Install a Hotfix on the Security Gateway / each Cluster Member / Scalable Platform Security Group:
Note - Install this hotfix, if in your environment it is not possible to enable the IPS Software Blade or it is not possible to use one of the default Threat Prevention profiles.
Hotfixes:
| Version | Hotfix | Prerequisite |
| R82 | (TAR) | R82 Jumbo Hotfix Accumulator, Take 12 |
| R81.20 | (TAR) | R81.20 Jumbo Hotfix Accumulator, Take 99 |
| R81.10 | (TAR) | R81.10 Jumbo Hotfix Accumulator, Take 174 |
| R81 | (TAR) | R81 Jumbo Hotfix Accumulator, Take 107 |
Notes:
For hotfix installation instructions, refer to sk168597 - How to install a Hotfix.
If at this time you cannot install the required Jumbo Hotfix Accumulator Take (listed in the column "Prerequisite") on your Security Gateway / Cluster, then contact Check Point Support to get this hotfix for your specific environment.
A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.
Customers with the versions R80.30, R80.30SP, and R80.40 need to upgrade to one of the supported versions and install the provided hotfix.
Option 2 - Enable the IPS Software Blade and use one of the default Threat Prevention profiles.
Note - If in your environment it is not possible to enable the IPS Software Blade or it is not possible to use one of the default Threat Prevention profiles, then follow "Option 1" above.
- Make sure the IPS Software Blade is enabled:
- On the left panel, click Gateways & Servers.
- Double-click the Security Gateway / Cluster object.
- On the General Properties page, click the Threat Prevention tab.
- If in the left section, you selected Custom Threat Prevention:
- In the right section select the IPS Software Blade.
- In the IPS First Time Activation window, select According to the Threat Prevention policy and click OK.
- Click OK to close the Security Gateway / Cluster object.
- Make sure the Custom Threat Prevention policy for this Security Gateway / Cluster uses one of the default Threat Prevention profiles:
Note - Follow this step if in the Security Gateway / Cluster object > on the General Properties page > on the Threat Prevention tab > in the left section, you selected Custom Threat Prevention. The Autonomous Threat Prevention policy uses the required IPS settings.
- On the left panel, click Security Policies.
- In the Threat Prevention section, click Custom Policy.
- Refer to the Action column in each rule.
Make sure this column shows one of these default Threat Prevention profiles:
- Basic
- Optimized (recommended)
- Strict
To select one of the default Threat Prevention profiles in a rule:
- Right-click the Action column in the rule.
- Select one of the default Threat Prevention profiles.
- Install the Threat Prevention policy.
NOTE
This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.
Article Properties
Access Level: General
Status: Approved by TAC
Date Created: 2025-05-29
Last Modified: 2025-09-14