Executive brief
F5 BIG-IP networking devices are susceptible to a denial-of-service vulnerability when processing specific types of encrypted traffic. An attacker can send specially crafted network data to a virtual server, causing the core traffic management component to crash. This results in a complete interruption of network services and application delivery managed by the affected device.
Technical details
A vulnerability classified as an infinite loop (CWE-835) exists in the F5 BIG-IP Traffic Management Microkernel (TMM). The issue is triggered when a Client SSL profile is configured with 'Allow Dynamic Record Sizing' on a UDP-based virtual server. An unauthenticated remote attacker can send undisclosed network traffic that causes TMM to terminate, leading to a denial-of-service (DoS) condition. The vulnerability affects multiple BIG-IP modules including LTM, APM, AFM, and ASM across versions 16.1.x, 17.5.x, and 21.0.0. F5 has provided mitigation guidance in advisory K000160901.
Affected products
- F5 BIG-IP Access Policy Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Advanced Firewall Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Local Traffic Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
- F5 BIG-IP Application Security Manager 16.1.0 - 16.1.6, 17.5.0 - 17.5.1, 21.0.0
Timeline
- 2026-05-13: advisory: Initial publication of the vulnerability advisory