> Source: [sk183980](https://support.checkpoint.com/results/sk/sk183980)

# sk183980 - Cluster node unexpectedly reboots after a prolonged freeze in R81.20 Jumbo Hotfix Accumulator Take 99

| Property | Value |
|----------|-------|
| Solution ID | sk183980 |
| Date Created | 2025-09-25 |
| Last Modified | 2025-09-29 |
| Technical Level | General |
| Products | Security Gateway |
| Versions | R81.20 |
| OS | Gaia |

## Symptoms

- * Cluster node unexpectedly reboots after a prolonged freeze (approximately 50 minutes) in R81.20 Jumbo Hotfix Accumulator Take 99.

* No clear cause found in standard system logs (`/var/log/dump/usermode/`).

* The system generates a large kernel memory dump (vmcore) file at the time of the incident.

* There are repeated incidents of long reboot times and system instability.

* Kernel logs indicate a page fault and unexpected exit in the `fw_worker_10` process, specifically in the `cpas_free_pkt_buf_ex` function.

* Errors related to connection handling and DNS response matching appear in kernel logs prior to the unexpected exit.

* Example kernel log output:

  `
  [timestamp] page fault in process fw_worker_10 at cpas_free_pkt_buf_ex`  
  `
  [timestamp] connection handling error: DNS response mismatch`  
  `
  [timestamp] system freeze detected, initiating automatic reboot`  
  `
  `

## Cause

The underlying cause is a kernel-level unexpected exit in the `fw_worker_10` process, specifically in the `cpas_free_pkt_buf_ex` function. This occurs because of a page fault during connection cleanup, likely linked to a memory management issue in the Firewall kernel module.

The unexpected exit results in a system freeze followed by an automatic reboot. Analysis of multiple kernel memory dump (vmcore) files confirms the same backtrace and unexpected exit signature, indicating a persistent issue in R81.20 Jumbo Hotfix Accumulator 99, affecting connection and packet buffer handling.

## Solution

This problem was fixed. The fix is included starting from:

* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 36
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 115

Check Point recommends to always upgrade to the [Recommended version](https://support.checkpoint.com/results/sk/sk95746) ([Security Gateway](https://support.checkpoint.com/product/73) / [VSX](https://support.checkpoint.com/product/359) / [Security Management Server](https://support.checkpoint.com/product/184) / [Multi-Domain Security Management Server](https://support.checkpoint.com/product/166) / [SmartConsole](https://support.checkpoint.com/product/191)).

If you choose not to upgrade, [contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for your version.

A Support Engineer will make sure the Hotfix is compatible with your environment before providing it.  
For faster resolution and verification, collect these files:

1. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Management Server involved in the case.
2. [CPinfo](https://support.checkpoint.com/results/sk/sk92739) file from the Security Gateway / each Cluster Member involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://support.checkpoint.com/results/sk/sk168597).

If you do not wish to upgrade to the above Takes:

1. [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a Hotfix for this issue.
2. Prepare the Hotfix installation:
   1. Take a Gaia OS snapshot to allow system restoration if needed.
   2. Update the Check Point Upgrade Service Engine (CPUSE) Agent to the latest version.
3. Download the Hotfix package with CPUSE. Follow standard CPUSE installation procedures for your environment.
4. Confirm Hotfix installation.
5. Monitor the system for stability and the absence of the previously observed symptoms.

**Important Note** : The Hotfix is compatible only with R81.20 Jumbo Hotfix Accumulator 99. If you upgrade to a newer version, [contact Check Point Support](https://support.checkpoint.com/results/sk/sk178777) and request a ported Hotfix from the Check Point Technical Assistance Center (TAC).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
