Executive brief
F5 BIG-IP is a suite of networking devices used to manage and secure enterprise web traffic. A vulnerability in the DNS caching feature allows a remote attacker to send specific network traffic that crashes the system's core processing engine. This results in a complete service outage, preventing legitimate users from accessing applications protected or managed by the affected BIG-IP device.
Technical details
A denial-of-service vulnerability exists in F5 BIG-IP when a DNS profile with DNS cache is enabled on a virtual server. The issue is rooted in an 'Access of Uninitialized Pointer' (CWE-824) within the Traffic Management Microkernel (TMM). A remote, unauthenticated attacker can send undisclosed network traffic to the virtual server, triggering a TMM crash and subsequent system restart. This affects multiple BIG-IP modules including DNS, LTM, AFM, and APM across versions 16.1.x, 17.5.x, and 21.0.0. F5 has released advisory K000160945 to address the issue.
Affected products
- F5 BIG-IP DNS 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
Timeline
- 2026-05-13: advisory: Initial publication of the vulnerability advisory