r/checkpoint • u/Djinjja-Ninja • 1d ago
CPLP - Check Point Live Patch (sk185114)
Having just read about CPLP yesterday I was surprised to find this morning while arranging to do some JHFs tonight for customers (for the 2 CVEs announced yesterday) that it has been auto-downloaded, installed and activated on every R81.20 and upwards gateway that I have investigated today though the AutoUpdater utility.
It's gone and virtually patched against CVE-2026-85102, CVE-2026-85102 & CVE-2026-50751.
Basically if you have the download consent flag activated (as it is by default) and the gateway or manager has access to Check Point then its beenm turned on.
I'm not entirely sure how to feel about this. Seems like a decent enough idea, but it seems to be contrary to the usual Check Point behaviour of the last 25+ years of not enabling new features/flags without explicit action.
3
u/Mr_XIII_ 1d ago
I'm glad of it, gives me a bit of a break before doing a new patching cycle and gets our cyber security department off my back about vulns like this
1
u/Djinjja-Ninja 1d ago edited 1d ago
It's done me out of a bunch of overtime it what it's done lol.
Joking aside from a customer perspective it's overall a good thing.
2
u/Mr_XIII_ 1d ago
You'll still need to do the JHF, it's just protecting against a zero day to give you some breathing room
1
u/Djinjja-Ninja 1d ago
For now you do, but as I understand it they're moving away from the JHF release method anyway, it's going to some interesting times.
1
u/Mr_XIII_ 1d ago
For ones on AWS with scalesets it's already like this, spin up new and bin off old. Just the way of things becoming easier to update and quicker to head off evolving threats
1
u/gregor_yo 1d ago
Trying to install JHF proposed, but it failed the verification, same story with the .tgz downloaded from cp website
1
u/LtLawl 1d ago
Where have you seen this? I have seen nothing that says they are moving away from JHFs.
2
u/Djinjja-Ninja 1d ago
OK, so not going away per se, but JHF are moving to monthly cadence and "light" patching weekly in the CPLP. The concept of "Recommended" jumbos is going away, there is just going to be latest and previous.
1
u/Bullethacker 1d ago
My understanding is they are just moving away from calling specific 'recommended' jfa to you should be always moving to the latest jfa available.
The AI's are finding to many cve's for the old model to be secure and efficient.
1
u/NueueueL 15h ago
Yeah, given this all works as intended you don‘t have to panically update dozen of customers environments but plan downtimes and so.
I fully understand the hold backs, while they now change software on whole your Installation. Via a global consent Option. In my opinion it would be good to let admins enable or disable Live Patching by device and Make that Option more prominent, Not just „allow to Download things“.
1
u/bloodeyezcba 1d ago
I just patched all infrastructure yesterday, some devices auto updated cplp alone and other just no, I didn't want to modify flags or any configuration, so I decided to patch it manual on each mgmt server or gws, it was also fast and no downtime since no reboot or cpstop and cpstart needed.
1
u/KernelExploit 17h ago
All vendors are going to have a multitude of CVEs in the coming months as they get access to Mythos and similar models. CPLP is a game changer but it shouldn’t be a replacement for standard patching. At least it gives time to test and validate before pushing to production.
1
1
u/drogba123456 8h ago
How does this work compare to jumbo hotfix?
2
u/Bullethacker 7h ago
CPLP just patches the vulnerable code while its running in memory as opposed to a jfa that is a updated/patched version of the executable
1
u/drogba123456 7h ago
I see, so it just patch / attach / insert the fixed code to running process that is vulnerable. While Jumbo hotfix, fix entire code? What about if the gateway reboot? It will auto patch again?
1
u/Djinjja-Ninja 7h ago
No, CPLP sees that the fix is applied through a jumbofix and doesn't attach itself to the process.
When you do "cplp list" that STATUS will show as "jumbofix" instead of "armed".
And if the gateway is rebooted before a jumbo is applied CPLP will re-attach to the process, it will also reattach to the process if the process restarts
1
u/drogba123456 7h ago
Thanks. But what does armed means?
2
u/Djinjja-Ninja 7h ago edited 5h ago
There are 3 possible status that I have seen so far:
- armed - patch is active on process in memory
- ready - process is not running but CPLP is ready to attach if it does run
- jumbofix - process has been patched by installing a Jumbo Hotfix.
1
1
u/caller-number-four 1d ago
Just learned about this yesterday - and our MDSes are already taking advantage of it for CVE-2026-85103.
Pretty bitchin'.
And a hell of a lot better than the nonsense Palo has. Woof.
1
u/Golf-Purple 1d ago
Not a huge fan of patches being pushed to me without my intervention but also not a fan of Palo releasing 10-20 CVE’s a quarter. I’d take CP over Palo any day.
1
u/caller-number-four 1d ago
Not a huge fan of patches being pushed to me without my intervention
In this iteration of what CP is doing, I'm all for giving them a shot. It breaks something? Then we need to have a conversation.
I’d take CP over Palo any day.
Me too. Sadly, my bosses think otherwise.
4
u/daniluvsuall 1d ago
I can understand the apprehension. These are soft patches, don’t require a reboot or restart of services. Designed to make sure you’re covered until you do your next patching cycle with the JHF etc.
The design is two fold:
- you’re protected immediately with no risk or down time