> Source: [sk184419](https://support.checkpoint.com/results/sk/sk184419)

# sk184419 - UPPAK memory buffer leak may occur when MDPS enabled and IPv6 disabled

| Property | Value |
|----------|-------|
| Solution ID | sk184419 |
| Date Created | 2025-12-10 |
| Last Modified | 2026-01-08 |
| Technical Level | General |
| OS | Gaia |

## Symptoms

- * The ClusterXL cluster transitions into an Active/Active state, with both Security Gateway members becoming Active simultaneously instead of maintaining proper Active/Standby roles.
* Frequent port flapping and loss of Cluster Control Protocol (CCP) communication between members.
* Repeated failover events and state changes (Active, Active(!), Down, Standby, Lost) appeared in system logs.
* Warnings may be observed in the $FWDIR/log/fwk.elg log:  
  `fwmultik_process_entry: no corresponding ipv6 instance `  
* Allocation failures in /var/log/usim_x86.elg:  
  `[UPPAK];fwk_snd_alloc_mbuf_for_fw: failed to alloc mbuf for fw`  
  `
  [UPPAK];m_get: allocation failure`

## Cause

On UPPAK-based Security Gateways with MDPS enabled and IPv6 disabled, IPv6 Neighbor Discovery packets trigger an UPPAK buffer leak. These buffers are not properly released, affecting Security Gateway traffic processing and maintain cluster communications.  
This resource exhaustion leads to split brain conditions where both cluster members become active simultaneously, resulting in service outages.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 60
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 122

If you choose not to upgrade, Check Point can supply a **Hotfix** . [Contact Check Point Support](https://www.checkpoint.com/support-services/.contact-support/) to get a Hotfix for this issue.  
A Support Engineer will make sure the Hotfix is compatible with your environment before providing the Hotfix.  
For faster resolution and verification, please collect [CPinfo files](http://supportcontent.checkpoint.com/solutions?id=sk92739) from the Security Management Server and Security Gateways involved in the case.

**Hotfix installation instructions:**   
Refer to [sk168597 - How to install a Hotfix](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk168597).

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
