# Security Gateway stops forwarding traffic during HTTP/2 sessions

**Product**: Anti-Virus, Security Gateways, Threat Emulation  
**Version**: R81.20, R82  
**Last Modified**: 2026-05-06

## Symptoms

- _/var/log/messages_ shows these messages:

```
kernel:[SIM4];cpaq_cbuf_send: cpaq_cbuf_call_api_end_ex failed
kernel:[SIM4];cpaq_cbuf_send_buffer: send chunk num 0 failed
kernel:[SIM4];sim_cphwd_stats_cb: failed to create cpaq buffer
```

- _fwk_softlock.elg_ file shows persistent soft lockups with these logs:

```
[instance_]: Received thread_blocker signal
[instance_]: [1] 0x529dd8d0 [/lib64/libpthread.so.0] (offset 0xf8d0)
[instance_]: [2] ws_http2_frame_queue_get_amount_of_bytes_by_status.constprop.1102 [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_optimized_9.so] (offset 0xb87ff0)
[instance_]: [3] ws_http2_pass [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_optimized_9.so] (offset 0xa3e085)
[instance_]: [4] ws_http2_handle_stream_action [/opt/CPsuite-R81.20/fw1/lib/libfw_kern_64_us_optimized_9.so] (offset 0xa43946)
[instance_]: [5] ws_connection2_read_handler
```

## Cause

HTTP/2 frame queues can become filled with streams stuck in a hold state. This situation can cause `ws_http2_frame_queue_get_amount_of_bytes_by_status` to consume more resources than intended.

## Solution

This problem was fixed. The fix is included in:

- [Check Point R82.10](https://support.checkpoint.com/results/sk/sk183506)  
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 44  
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 119

If you choose not to upgrade, Check Point can supply a **Hotfix**. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.

For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**

Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

#### NOTE

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

## Article Properties

**Access Level**: General  
**Status**: Approved by TAC  
**Date Created**: 2025-09-03  
**Last Modified**: 2026-05-06
