Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Adam276
Collaborator

Check Point Live Patch and previous JHFA versions

How far back does Checkpoint provide live patches for JHFA versions?  I haven't found any guidelines for this in the SK1000155 on this.  Is it 1, 2, 3, all versions previous from recommended?  I feel this is important to know in the releases.

Since it was just released several months ago I suspect maybe not so far back right now.  So I guess this is more 2 questions.

1.  How far back do the existing patches go for previous JHFA versions.

2. Going forward, How far back will the live patches go for previous JHFA versions?

0 Kudos
5 Replies
simonemantovani
MVP Diamond CHKP MVP Diamond CHKP
MVP Diamond CHKP

From my knowledge, and based on thise sentence:

  • Automatic stand-down - When the matching Hotfix or Jumbo Hotfix Accumulator containing the fix is installed, CPLP recognizes a fix is present and stops applying the patch."

CPLP reports only the vulnerabilities not covered by the major release and JHF currently installed; if you have already installed the latest JHF that covers also the latest released CVE, CPLP should not display anything because there isn't any vulnerability to patch.

Considering the purpose of CPLP, it's a tool that temporary mitigate the CVE, offering to the customer enough time to plan the installation of the JHF.

0 Kudos
Adam276
Collaborator

I am not asking what happens when you update to a newer JHFA.  That is understood.  I saw information about that.  It won't apply the patch if a newer JHFA fixes it.

I am asking how far back in JHFA versions the patch will apply to.  There are many JHFAs available that a customer might be on for a specific version of Checkpoint R81.20 or 82, etc.  How many older JHFA versions back can we expect live patch to be able to patch the executables?

0 Kudos
simonemantovani
MVP Diamond CHKP MVP Diamond CHKP
MVP Diamond CHKP

It depends of the installed JHF, I mean, as an example, you installed the JHF 1, after a couple of weeks a CVE is released reporting that JHF 1 is vulnerable; CPLP will cover this CVE; you decide to not install the JHF 2 (that fixes the CVE), after another month a new CVE is released, and JHF 1 and JHF 2 are vulnerable, CPLP will cover both CVE until you perform the upgrade to JHF 3 that fix the issue.

If your JHF is vulnerable to several CVE since it has been installed to today, and you didn't installed any further JHF, CPLP will cover, obviously this is a borderline case. Sooner or later you should install the latest JHF.

I hope I’ve made myself clear, I think I could also made some test in a lab environment to confirm this.

0 Kudos
Adam276
Collaborator

It seems like that information should be posted and available with the live patch information.  Not only what major version, but what minor JHFA version is also compatible with a specific live patch.  It seems to me that we shouldn't have to guess if a live patch will actually patch a gateway at a specific JHFA or not.  While wait and check the gateway and see is an answer, I would think that should be documented so that we know what to expect ahead of time.

I was looking for official documentation about it and their stance on it.

simonemantovani
MVP Diamond CHKP MVP Diamond CHKP
MVP Diamond CHKP

Hello

I agree that maybe further information on how CPLP works could be added in the documentation; as far as I can tell, if you look every SK related to CVE released by Check Point reports if it's covered by CPLP, if it's not mentioned, CPLP can't fix the specific CVE.

So, the output of cplp list display information about all the CVEs not fixed in the release and JHF in use and CPLP can fix.

For example, this is the output of a Security Gateway R81.20 without JHF (fresh install):

ID(PATCH:PROC) STATUS MODE PIDS INSTALLED COMMENT
--------------------------------------------------------------------------
cpcert:cpca* ready livepatch 0/0 2026-09-17 08:54:34 CVE-2026-85102 CVE-2026-85103
cpcert:iked* ready livepatch 0/0 2026-09-17 08:54:34 CVE-2026-85102 CVE-2026-85103
cpcert:vpnd* ready livepatch 0/0 2026-09-17 08:54:34 CVE-2026-85102 CVE-2026-85103
cpcert:vpnrad* ready livepatch 0/0 2026-09-17 08:54:34 CVE-2026-85102 CVE-2026-85103
cpcert:wstlsd* ready livepatch 0/0 2026-09-17 08:54:34 CVE-2026-85102 CVE-2026-85103
cpcert_cprid:cprid* armed livepatch 1/1 2026-09-17 08:54:30 CVE-2026-85102 CVE-2026-85103
cpikev2:iked* ready livepatch 0/0 2026-09-17 08:54:36 CVE-2026-85102 CVE-2026-85103
vpn1:iked* ready livepatch 0/0 2026-09-17 08:54:26
vpn1:vpnd* ready livepatch 0/0 2026-09-17 08:54:26

It reports only two CVEs:

  • CVE-2026-85102
  • CVE-2026-85103

These are CVEs related to Security Gateway only, and these are CVE that can be fixed by CPLP; for example, this CVE:

 https://support.checkpoint.com/results/sk/sk185153

It affects my gateway, but is not covered by CPLP, so it's no listed in the output of cplp list command.

Just to recap, if you have a Security Gateway with the latest JHF installed, a new CVE is published, and this CVE is covered by CPLP, than it will be showed in the output of CPLP command.

If your gateway has an older JHF, CPLP will lists only the CVEs that can affect your gateway and that it covers.

I’m sure this logic is clear to you too; I was just wrapping up the point—I hope I haven’t bored you.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events