> Source: [sk184446](https://support.checkpoint.com/results/sk/sk184446)

# sk184446 - CPdiag caused FWK hanging

| Property | Value |
|----------|-------|
| Solution ID | sk184446 |
| Date Created | 2025-12-16 |
| Last Modified | 2025-12-22 |
| Technical Level | Advanced |
| Products | Hardware |
| Versions | Not Version-Specific |
| OS | Gaia |

## Symptoms

- * All of the below symptoms apply to this issue only if the following conditions are met:   
  1. The CPdiag process is running (verify using ps auxf \| grep cpdiag).   
  2. The MD5 checksum of the file /opt/CPdiag/conf/cpdiag_dynamic_config.dat is 1edd37e822acf87b1bd14ca74265de40.
* From /var/log/thread_blocker_device64.elg: Blockers related to the FWK process.
* From /var/log/messages: Dec 16 08:38:48 2025 sg-external-ch01-01 kernel:\[SIM4\];cpaq_cbuf_send: cpaq_cbuf_call_api_end_ex failed Dec 16 08:38:48 2025 sg-external-ch01-01 kernel:\[SIM4\];cpaq_cbuf_send_buffer: send chunk num 0 failed Dec 16 08:38:48 2025 sg-external-ch01-01 kernel:\[SIM4\];sim_cphwd_stats_cb: failed to create cpaq buffer
* From $FWDIR/log/fwk_wd.elg: thread_blocker_monitor_periodic_timeout_exp_check: tid 12524 exceeded its timeout(10000) thread_blocker_monitor_periodic_timeout_exp_check: cur_time: 16047740234 reporting_time: 16044102124

## Cause

Between December 14 and December 16, CPDIAG deployed a dynamic configuration update that introduced a script. The script aggressively scanned processes and memory, which overloaded CPU and memory resources. The overload disrupted traffic and made systems unstable.  
Root Cause:  
The script consumed excessive resources during scanning operations.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
