| Solution | The fnbamd daemon crashes at __fnbamd__dns_maintainer may lead to high CPU utilization and authentication-related issues on the FortiGate device. Crashlog example: 2185: 2025-11-11 10:25:41 <23364> firmware FortiGate-101F v7.4.9,build2829b2829,250924 (GA.M) (Release) 2186: 2025-11-11 10:25:41 <23364> application fnbamd 2187: 2025-11-11 10:25:41 <23364> *** signal 11 (Segmentation fault) received *** 2188: 2025-11-11 10:25:41 <23364> Register dump: 2189: 2025-11-11 10:25:41 <23364> R0: 000000555a6a96e0 R1: 0000005561144388 R2: 000000555a6a96e0 2190: 2025-11-11 10:25:41 <23364> R3: 00000000000009d1 R4: 0000005561152460 R5: 000000000000007e 2191: 2025-11-11 10:25:41 <23364> R6: 0000000000000007 R7: 00000000ffffffaf XR: 0000000000000039 2192: 2025-11-11 10:25:41 <23364> R9: 0000007ff1d777f8 R10: 000000000000000a R11: 0000000000000000 2193: 2025-11-11 10:25:41 <23364> R12: 0000000000001110 R13: 0000000000000000 R14: 0000000000000000 2194: 2025-11-11 10:25:41 <23364> R15: 0000000000000000 IP0: 0000007f9795a048 IP1: 0000007f978691c0 2195: 2025-11-11 10:25:41 <23364> PR: 0000000000000000 R19: 0000000000000000 R20: 000000555a6a9000 2196: 2025-11-11 10:25:41 <23364> R21: 0000005558902000 R22: 000000555cb27970 R23: 00000055588cd598 2197: 2025-11-11 10:25:41 <23364> R24: 00000055588c7608 R25: 00000000000000c8 R26: 00000055588c7000 2198: 2025-11-11 10:25:41 <23364> R27: 0000000000000000 R28: 0000000000000000 FP: 0000007ff1d788e0 2199: 2025-11-11 10:25:41 <23364> fault_address: 0000000000000000 sp: 0000007ff1d788e0 2200: 2025-11-11 10:25:41 <23364> pc: 00000055561f21d0 lr: 00000055561f21c8 2201: 2025-11-11 10:25:41 <23364> pstate: 20000000 (nzCv daif -PAN -UAO)
2202: 2025-11-11 10:25:41 <23364> Backtrace: 2203: 2025-11-11 10:25:41 <23364> [0x55561f21d0] => /bin/fnbamd {0x5555555000} => __fnbamd_dns_maintainer at ././daemon/fnbamd/fnbamd_dns.c:60 (discriminator 2) 2204: 2025-11-11 10:25:41 <23364> [0x55582d90b8] => /bin/fnbamd {0x5555555000} => timer_callback_wrapper at ././migbase/sysapi/daemon/daemon_api.c:19 2205: 2025-11-11 10:25:41 <23364> [0x55570bc134] => /bin/fnbamd {0x5555555000} => check_expiration at ././migbase/sysapi/timer/timer.c:205 2206: 2025-11-11 10:25:41 <23364> [0x55570ba738] => /bin/fnbamd {0x5555555000} => _fg_avl_traverse at ././migbase/sysapi/timer/fg_avl_tree.c:45 (inlined by) fg_avl_traverse at ././migbase/sysapi/timer/fg_avl_tree.c:64 2207: 2025-11-11 10:25:41 <23364> [0x55582d8b70] => /bin/fnbamd {0x5555555000} => daemon_main at ././migbase/sysapi/daemon/daemon.c:319 2208: 2025-11-11 10:25:41 <23364> [0x5556211a24] => /bin/fnbamd {0x5555555000} => fnbamd_main at ././daemon/fnbamd/fnbamd_main.c:130 2209: 2025-11-11 10:25:41 <23364> [0x5555945050] => /bin/fnbamd {0x5555555000} => fortiexec_call_main at ././sysinit/fortiexec.c:806 2210: 2025-11-11 10:25:41 <23364> [0x7f97810f24] => /lib/libc.so.6 {0x7f977f0000} => ?? ??:0 2211: 2025-11-11 10:25:41 <23364> fortidev 6.0.2.0008 2212: 2025-11-11 10:25:41 the killed daemon is /bin/fnbamd: status=0xb00
In the above crashlog, the process crashed 5 times. The issue is triggered when the FortiGate is unable to retrieve a CA certificate externally. This results in improper handling of DNS request cleanup (dns_request delete), leading to memory access issues and eventual crash of the fnbamd daemon.
A workaround for this issue is importing the correct CA to the FortiGate.
The issue is resolved in FortiOS v7.4.12:2889, FortiOS v7.6.7:3675. |