CVE-2026-42920: 
F5 BIG-IP Virtual Edition Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-42920 is a Denial of Service vulnerability in F5 BIG-IP affecting the Traffic Management Microkernel (TMM). When a Client SSL profile is configured with "Allow Dynamic Record Sizing" on a UDP virtual server, undisclosed traffic can cause the TMM process to terminate. The vulnerability was published on May 13, 2026, and affects BIG-IP versions 17.1.0 < 17.1.3.1, 17.5.0 < 17.5.1.4, 21.0.0 < 21.0.0.1, and 16.1.x (all versions); software versions that have reached End of Technical Support (EoTS) are not evaluated. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).

Détails techniques

The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop), indicating that specially crafted network traffic triggers an unrecoverable loop condition within the TMM process, ultimately causing it to terminate. The attack vector is network-based, requiring no authentication, no user interaction, and no special privileges — only that the target BIG-IP device has a Client SSL profile with "Allow Dynamic Record Sizing" enabled on a UDP virtual server. The specific traffic pattern that triggers the condition has not been publicly disclosed by F5. No public proof-of-concept exploit code is known to exist at this time (GitHub Advisory, F5 Advisory).

Impact

Successful exploitation causes the TMM — the core data-plane process responsible for handling all traffic on F5 BIG-IP appliances — to terminate, resulting in a complete loss of availability for all services managed by the affected BIG-IP instance. There is no confidentiality or integrity impact; the attack is purely a Denial of Service. Depending on the deployment context, a TMM crash could disrupt load balancing, application delivery, and SSL/TLS termination for all downstream applications, potentially affecting large numbers of end users and critical business services (GitHub Advisory, F5 Advisory).

Exploitabilité

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.072–0.098%, placing it in roughly the 27th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing F5 BIG-IP instances running affected versions (17.1.0 < 17.1.3.1, 17.5.0 < 17.5.1.4, 21.0.0 < 21.0.0.1, or 16.1.x) using tools such as Shodan or Censys, filtering for BIG-IP management interfaces or known service ports.
  2. Identify vulnerable configuration: Determine whether the target BIG-IP has a Client SSL profile with "Allow Dynamic Record Sizing" enabled on a UDP virtual server — this may be inferred from exposed service banners or configuration leakage.
  3. Send crafted UDP traffic: Transmit specially crafted (undisclosed) UDP traffic to the virtual server associated with the vulnerable Client SSL profile, designed to trigger the infinite loop condition in the TMM process.
  4. Achieve Denial of Service: The TMM process enters an unreachable exit condition (infinite loop) and terminates, causing all traffic handling on the BIG-IP device to cease and resulting in a service outage for all downstream applications (GitHub Advisory, F5 Advisory).

Indicateurs de compromis

  • Logs: Unexpected TMM process termination events in /var/log/tmm or /var/log/ltm; repeated TMM restart messages in BIG-IP system logs; core dump files generated in /var/core/ following TMM crashes.
  • Process: Absence of the tmm process or rapid TMM restarts observable via tmsh show sys tmm-info or system monitoring dashboards.
  • Network: Unusual or malformed UDP traffic directed at virtual servers with Client SSL profiles configured with "Allow Dynamic Record Sizing"; traffic anomalies coinciding with TMM crashes.
  • System: BIG-IP failover events in HA pairs triggered by TMM unavailability; SNMP traps or alerts indicating TMM process failure.

Atténuation et solutions de contournement

F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.1, 17.5.1.4, and 21.0.0.1. Organizations unable to upgrade immediately should disable "Allow Dynamic Record Sizing" on Client SSL profiles associated with UDP virtual servers if this feature is not operationally required. Additionally, implementing network-based access controls to restrict which sources can send traffic to affected UDP virtual servers can reduce exposure. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).

Réactions de la communauté

Coverage of CVE-2026-42920 has been limited to automated vulnerability tracking platforms and security aggregators such as VulDB, CVEFeed, and Eclypsium's May 2026 hardware fix summary. No notable independent researcher commentary or significant social media discussion has been identified. The vulnerability was detected by Tenable's Nessus scanner (plugin 316096), indicating it has been incorporated into standard vulnerability management tooling (Tenable Plugin, Eclypsium Summary).

Ressources additionnelles


Source: Ce rapport a été généré à l’aide de l’IA

Apparenté F5 BIG-IP Virtual Edition Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_application_security_manager
NonOuiMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_application_security_manager
NonOuiMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiMay 13, 2026
CVE-2026-63020LOW2.3
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
NonOuiSep 02, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités