Executive brief
A vulnerability in F5 BIG-IP devices can allow an attacker to crash the system's core traffic processing engine. This affects devices configured with specific Policy Enforcement Manager (PEM) rules used for traffic classification and analytics. An exploit would result in a complete service outage, preventing the device from handling network traffic and potentially disrupting business operations.
Technical details
This vulnerability is classified as a Use-After-Free (CWE-416) within the Traffic Management Microkernel (TMM) of F5 BIG-IP. It is triggered when specific PEM iRules are configured on a virtual server, specifically those utilizing commands such as CLASSIFICATION::, CLASSIFY::, PEM::, PSC::, or urlcatquery. A remote, unauthenticated attacker can send specially crafted network traffic to the affected virtual server to cause TMM to terminate, resulting in a denial-of-service (DoS). The issue affects multiple BIG-IP modules including PEM, LTM, AFM, and APM across versions 16.1.x, 17.5.x, and 21.0.0. F5 has released a vendor advisory with mitigation and patching information.
Affected products
- F5 BIG-IP PEM 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP APM 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP AFM 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP LTM 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
Timeline
- 2026-05-13: advisory: Initial publication of the vulnerability advisory