Troubleshooting Tip: Frequent ipsengine daemon crashes (Signal 11) causing Intrusion Prevention Scanning Failures
| Description | This article describes an issue where the ipsengine daemon repeatedly crashes with Signal 11, resulting in intrusion prevention scanning failures. Due to these crashes, certain websites or traffic sessions may be blocked by the FortiGate because the Intrusion Prevention System (IPS) is unable to properly inspect the traffic, leading to IPS scanning failure events. |
| Scope | FortiGate v7.4.10, v7.4.11. |
| Solution | Frequent ipsengine crashes may be seen in the command output 'diagnose debug crashlog read'.
9913: 2026-02-02 10:26:42 <11933> firmware FortiGate-4400F v7.4.11,build2878b2878,260126 (GA.M) (Release) The decoded crashlog is as follows:
This issue occurs due to improper HTTP header offset tracking leading to potential buffer overflow/underflow when buffers are modified in place. |
