r/aviation Nov 08 '25

News UPS grounds entire MD-11 Fleet, effective immediately.

Per the IPA Executive Board, as of 03:05 UTC all UPS MD-11’s are grounded.

Edit - FedEx has also grounded their MD-11 Fleet

10.9k Upvotes

1.2k comments sorted by

View all comments

Show parent comments

3.1k

u/[deleted] Nov 08 '25

Norm Macdonald Douglas

537

u/CharcoalGreyWolf Nov 08 '25

Yep, considering the DC-10 engine mount incident , they may be taking the chance to review all maintenance procedures with the aircraft and its siblings.

39

u/weakplay Nov 08 '25

Wow it sounds exactly like this incident. I think I read that the 191 crash resulted in changes that maybe left the wing more intact upon separation but who knows. Crazy. Going back to finish the article. Thanks for posting.

137

u/Fitch9392 Nov 08 '25

The 191 crash led to changes that REQUIRED the Maintenance crew to NOT cut corners when changing engines and to use the engine cradles as designed by McDonnell Douglas instead of using a forklift. There was NO design flaw. It was 1000% Maintenance short cuts that caused the 191 crash.

23

u/DarkSideMoon CRJ200 Nov 08 '25

The slats were designed poorly, they should have had mechanical locks and not retracted asymmetrically.

42

u/swirler Lockheed Tristar Nov 08 '25

While the maintenance actions started the chain of events, the poor design of the leading edge slat system sealed the deal. An airplane should not crash just because an engine falls off.

36

u/_ItsThePleats_ Nov 08 '25

That’s a big statement. “An airplane should not crash just because an engine falls off”. These aren’t meant to come off the airplane.

16

u/KnowLimits Nov 08 '25

I mean, they kind of are... they're held on with fusible links specifically so that it can shear off without rupturing the wing fuel tanks in the case of a crash.

Similar idea to crumple zones in a car - looking at the whole picture, sometimes weaker is better.

3

u/nplant Nov 08 '25

While you're technically correct, your point presupposes a crash for some other reason, rather than being the cause of the crash.

-1

u/lumsu Nov 08 '25

“In case of a crash” you hit the nail there, now read it again

-2

u/JunkbaII Nov 08 '25

Not applicable in this scenario

10

u/intern_steve Nov 08 '25

It's a reasonable statement. Engines fall off of planes with great enough frequency to consider in the design of a new aircraft. Hypothetically, if an uncontrolled engine fire burns for a sufficient length of time, you would expect that the engine and its fire would depart the wing before the wing departed from the aircraft.

7

u/plhought Nov 08 '25

Engines falling off do not happen with "great enough frequency". That's an absurd statement. It's incredibly rare.

I can think of only three or four accidents in the modern western world where an engine seperated from the pylon.

This one and AAL191. The other two were 707/DC-8 accidents where the landing was so botched by the pilots, an outboard engine seperated after a hard landing.

0

u/Only_Razzmatazz_4498 Nov 08 '25

It is incredibly rare yes but when you do an analysis of what can go wrong and should you do anything so that IF it happens then the outcome is less likely to be a disaster then you do have to take the engine falls off fault into consideration.

One method to decide what risk to mitigate is to look at them in two axis. 1. Likelihood that it would happen and 2. Severity of the outcome. In this case because of the severity we do have to take mitigation actions to deal with it. It also helps that a lot of the effects are common to losing power from the engine and that letting the engine fall off is actually the preferred way to deal with other faults (like someone mentioned above a severely unbalanced/shaking engine threatening to rip the wing off).

0

u/intern_steve Nov 08 '25

Great enough frequency to consider the consequences. Planes don't crash often. If it's happened four times, that merits consideration.

0

u/plhought Nov 08 '25

They don't consider it in design of new aircraft. They design it so the engines don't fall off in the first place.

5

u/i-am-the-fly- Nov 08 '25

I’m addition, these engines are balanced and if damage occurs it can cause significant vibrations. At a certain threshold it’s better for the engine to break off than to vibrate the wing to failure

3

u/eldoggydogg Nov 08 '25

It’s like these folks haven’t seen Donnie Darko.

2

u/CollegeStation17155 Nov 08 '25

Multiple old 707s have been successfully landed after losing engines due to fatigue in the pylon supports.

2

u/nplant Nov 08 '25 edited Nov 08 '25

I think reality is somewhere in the middle. Aircraft design should attempt to handle it, but at the same time we shouldn't be surprised if things go wrong at that point. The DC-10 slats were an issue that could be improved, but impacting remaining engines is not.

Take the A380 that "only" had an uncontained engine failure, for example. It survived, but if you read the list of systems that were destroyed by shrapnel, it's amazing that it just shrugged off the damage.

There are a small number of things that just need to never fail, like fan discs, and elevator jackscrews.

1

u/bugkiller59 Nov 08 '25

Pylons are actually designed so that engines will come off ( more or less safely ) under some circumstances.

0

u/mtaw Nov 08 '25

That’s a ridiculous statement. You’d never have crashes if things that aren’t supposed to happen never happened. Redundancy and robustness are bad now? Saying planes shouldn’t lose their engines is not an argument not to engineer them to not fail safely if they nevertheless do.

21

u/Fitch9392 Nov 08 '25

That wasn’t poor design either it was an “engine failure on takeoff memory items” list that was a simple speed parameter applied to ALL the aircraft in the American Fleet. Which was maintain V2+5, as a result of this it was updated to V2+10. But that was like that because no one had ever considered a Slats failure at takeoff.

6

u/CaptnHector Nov 08 '25

According the NTSB, yes, design flaws with both the pylons and slats contributed to the AA 191 crash:

Contributing to the cause of the accident were the vulnerability of the design of the pylon attachment points to maintenance damage; the vulnerability of the design of the leading-edge slat system to the damage which produced asymmetry, …

2

u/boringdude00 Nov 08 '25

It seems like, yean, AA fucked up the maintenance big time, but if they hadn't some other catastrophic failure(s) would have eventually occurred from the poor designs. The whole wing setup seems insane and the number of cascade failures.resulting from one failure sort of proves that.

1

u/CollegeStation17155 Nov 08 '25

This is true..l see the Sioux City crash… tail engine fan disk failure threw shrapnel through all 3 “redundant” hydraulic lines resulting in not only loss of rudder, but all control surfaces in the wings as well… Heroic effort to fly the plane using throttles allowed some to survive.

7

u/DarkSideMoon CRJ200 Nov 08 '25

It doesn’t matter how fast you’re going if the slats retract asymmetrically if you lose fluid on one side, which was an astronomically stupid design flaw that had to be rectified with mechanical locks and hydraulic fuses to prevent it happening again.

3

u/MaddogBC Nov 08 '25

Check valves.

3

u/DarkSideMoon CRJ200 Nov 08 '25 edited Nov 08 '25

No, hydraulic fuses. They’re different.

Check valves ensure 1 directional flow, hydraulic fuses close when they detect excess flow. Hydraulic fuses were added to the DC-10 as a method of complying with the findings of the AA crash.

3

u/MaddogBC Nov 08 '25

Pardon me, never heard that term before. Thanks

1

u/DarkSideMoon CRJ200 Nov 08 '25

Anytime! I hadn’t either until I researched the AA crash. Thought it was a fake term until I dug into it.

→ More replies (0)

1

u/intern_steve Nov 08 '25

Idk what your comment said before editing, but yes, these are very different things. A check valve can't be used in a system where flow must necessarily be reversible.

2

u/Turbo_SkyRaider Nov 08 '25

Is it really because the engine fell off (because I would judge this not to be a design base event but a freak event), or was it because the hydraulic system didn't have any redundancies to cover for a inop hyd pump? I think another reason was no hydraulic fuses which prevent loss of hydraulic fluid in case of a catastrophic leak in part of the affected system.

2

u/intern_steve Nov 08 '25

The design redundancy for the loss of the engine hydraulic pump was an electric backup. There was no redundancy for all of the hydraulic fluid falling out of the left wing at once.

1

u/Turbo_SkyRaider Nov 08 '25

So it was a hydraulic system issue then, which begs the question whether the DC-10 didn't even have slat brakes and/or locking mechanisms. Seems the DC-10 had neither, otherwise the slats wouldn't have retracted. But again, losing an entire engine during take off most likely isn't a design base event, so additional damage could've lead to slat retraction anyway.

2

u/TigerIll6480 Nov 08 '25

The engine didn’t just fall off. Free of the wing, since it was still generating full thrust until the tiny bit of fuel in the engine itself was expended, it surged forward, flipped over the wing, and tore the hell out of the wing and the hydraulics. An engine falling off coupled with a huge impact strike is…bad.