Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
David_Evans
Advisor

Check Point Live Patch (CPLP)

Has anyone written a custom metric yet for Check Point Live Patch (CPLP) ?

Or anyone have any inside information into a built in metric coming "soon" before I spend a few hours writing one?

3 Replies
Bob_Zimmerman
MVP Gold
MVP Gold

I'm working on one right now, after discovering a lot of my firewalls don't actually have CPLP yet.

Duane_Toler
MVP Silver
MVP Silver

This should help:

# cplp list --json |jq -r '.|length'
77
# cplp list --json |jq -r '.[0] |keys'
[
  "active",
  "addr_hex",
  "all_pids",
  "anchor",
  "applied_at",
  "applied_by",
  "arch",
  "audit",
  "auto_select",
  "comm",
  "comment",
  "cover",
  "cover_detail",
  "cover_kind",
  "cover_reason",
  "cover_token",
  "fix_prefix",
  "host",
  "id",
  "lib_basename",
  "lib_path",
  "mode",
  "n_pids_armed",
  "n_pids_reverted",
  "n_pids_total",
  "name",
  "patch_id",
  "patches_dir",
  "pids",
  "proc_name",
  "status",
  "symbol",
  "unresolved",
  "unsupported",
  "unsupported_reason"
]

 

# cplp list --json |jq -r '.[0] '
{
  "active": true,
  "addr_hex": null,
  "all_pids": [
    23796
  ],
  "anchor": null,
  "applied_at": "2026-07-30T13:30:01Z",
  "applied_by": "admin",
  "arch": "i386",
  "audit": true,
  "auto_select": true,
  "comm": "cpca",
  "comment": "sk185152",
  "cover": "ok",
  "cover_detail": null,
  "cover_kind": null,
  "cover_reason": "x86 GA branch jaguar_main has no own patch; fell back to jumbo R82_jumbo_hf_main earliest build 998000024 -> libcpca_R82_jumbo_hf_main_998000024.so",
  "cover_token": null,
  "fix_prefix": "libcpca",
  "host": "bayou",
  "id": "cpca:cpca:3304b2df72",
  "lib_basename": "libcpca.so",
  "lib_path": "/opt/CPshrd-R82/lib/libcpca.so",
  "mode": "livepatch",
  "n_pids_armed": 1,
  "n_pids_reverted": 0,
  "n_pids_total": 1,
  "name": "cpca",
  "patch_id": "cpca:cpca:3304b2df72",
  "patches_dir": "/opt/cplp/patches",
  "pids": [
    23796
  ],
  "proc_name": "cpca",
  "status": "armed",
  "symbol": "fwcaHandShakerS::CheckConfig",
  "unresolved": false,
  "unsupported": false,
  "unsupported_reason": null
}

 

 

# cplp list --json |jq -r '. |map(select(.comment|contains("CVE-2026-85103"))) |length' 
30

# cplp list --json |jq -r '.[]|select(.comment|contains("CVE-2026-85103"))'
# ...
{
  "active": true,
  "addr_hex": null,
  "all_pids": [
    10485,
    9793,
    10583,
    10055,
    10188,
    10356,
    9932,
    9621,
    9857,
    9651,
    9710,
    9614,
    9610,
    9606
  ],
  "anchor": null,
  "applied_at": "2026-09-09T13:12:40Z",
  "applied_by": "admin",
  "arch": "i386",
  "audit": true,
  "auto_select": true,
  "comm": "wstlsd",
  "comment": "CVE-2026-85102 CVE-2026-85103",
  "cover": "ok",
  "cover_detail": null,
  "cover_kind": null,
  "cover_reason": "x86 jumbo branch R82_jumbo_hf_main build 998000024 is below the earliest jumbo patch build 998000028; no GA baseline installed, so the earliest jumbo build takes ownership -> libcpcert_R82_jumbo_hf_main_998000028.so",
  "cover_token": null,
  "fix_prefix": "libcpcert",
  "host": "bayou",
  "id": "cpcert:wstlsd:a6ec397432",
  "lib_basename": "libcpcert.so",
  "lib_path": "/opt/CPshrd-R82/lib/libcpcert.so",
  "mode": "livepatch",
  "n_pids_armed": 14,
  "n_pids_reverted": 0,
  "n_pids_total": 14,
  "name": "cpcert",
  "patch_id": "cpcert:wstlsd:a6ec397432",
  "patches_dir": "/opt/cplp/patches/cpcert_2",
  "pids": [
    10485,
    9793,
    10583,
    10055,
    10188,
    10356,
    9932,
    9621,
    9857,
    9651,
    9710,
    9614,
    9610,
    9606
  ],
  "proc_name": "wstlsd",
  "status": "armed",
  "symbol": "fwAsnBits::Concat",
  "unresolved": false,
  "unsupported": false,
  "unsupported_reason": null
}
#...
'

 

# cplp status --all --json |jq -r '. |length'
77

# cplp status --all --json |jq -r '.[1] |keys'
[
  "addr_hex",
  "anchor",
  "arch",
  "comm",
  "label",
  "lib_path",
  "manifest_status",
  "mode",
  "name",
  "patch_id",
  "proc_name",
  "results",
  "source_file",
  "symbol"
]

# cplp status --all --json |jq -r '.[42]'
{
  "addr_hex": null,
  "anchor": null,
  "arch": "i386",
  "comm": "wstlsd",
  "label": "fwAsnBits::Concat",
  "lib_path": "/opt/CPshrd-R82/lib/libcpcert.so",
  "manifest_status": "armed",
  "mode": "livepatch",
  "name": "cpcert",
  "patch_id": "cpcert:wstlsd:a6ec397432",
  "proc_name": "wstlsd",
  "results": [
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "68509a13f7c3",
      "observed_status": "armed_clean",
      "pid": 10485,
      "reason": null,
      "runtime_addr_hex": "0xf775ed80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "68501a17f7c3",
      "observed_status": "armed_clean",
      "pid": 9793,
      "reason": null,
      "runtime_addr_hex": "0xf7796d80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "6850fa10f7c3",
      "observed_status": "armed_clean",
      "pid": 10583,
      "reason": null,
      "runtime_addr_hex": "0xf7734d80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "6850ea1af7c3",
      "observed_status": "armed_clean",
      "pid": 10055,
      "reason": null,
      "runtime_addr_hex": "0xf77d3d80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "68501a14f7c3",
      "observed_status": "armed_clean",
      "pid": 10188,
      "reason": null,
      "runtime_addr_hex": "0xf7766d80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "68507a18f7c3",
      "observed_status": "armed_clean",
      "pid": 10356,
      "reason": null,
      "runtime_addr_hex": "0xf77acd80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "68507a19f7c3",
      "observed_status": "armed_clean",
      "pid": 9932,
      "reason": null,
      "runtime_addr_hex": "0xf77bcd80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "68509a10f7c3",
      "observed_status": "armed_clean",
      "pid": 9621,
      "reason": null,
      "runtime_addr_hex": "0xf772ed80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "6850fa11f7c3",
      "observed_status": "armed_clean",
      "pid": 9857,
      "reason": null,
      "runtime_addr_hex": "0xf7744d80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "6850ca11f7c3",
      "observed_status": "armed_clean",
      "pid": 9651,
      "reason": null,
      "runtime_addr_hex": "0xf7741d80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "6850aa1af7c3",
      "observed_status": "armed_clean",
      "pid": 9710,
      "reason": null,
      "runtime_addr_hex": "0xf77cfd80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "6850aa13f7c3",
      "observed_status": "armed_clean",
      "pid": 9614,
      "reason": null,
      "runtime_addr_hex": "0xf775fd80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "6850aa19f7c3",
      "observed_status": "armed_clean",
      "pid": 9610,
      "reason": null,
      "runtime_addr_hex": "0xf77bfd80",
      "window_len": 6
    },
    {
      "action_at": "2026-09-09T13:12:40Z",
      "comm": "wstlsd",
      "exec_name": "wstlsd",
      "expected_state": "armed",
      "observed_bytes_hex": "68509a13f7c3",
      "observed_status": "armed_clean",
      "pid": 9606,
      "reason": null,
      "runtime_addr_hex": "0xf775ed80",
      "window_len": 6
    }
  ],
  "source_file": "/opt/cplp/patches/cpcert_2/cpcert_patch.json",
  "symbol": "fwAsnBits::Concat"
}
--
Ansible for Check Point APIs series: https://www.youtube.com/@EdgeCaseScenario and Substack
Elad_Chomsky
Employee
Employee

Hi @David_Evans ,

We’re currently working on an official Check Point Live Patch (CPLP) integration for Skyline as metrics. The ETA for full release is start of 2027. But this might change due to time constraints, I will follow up with the owner to share guidance for a custom script in the meantime. 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events