
PEACH
Un cadre d’isolation des locataires
CVE-2026-42920 is a Denial of Service vulnerability in F5 BIG-IP affecting the Traffic Management Microkernel (TMM). When a Client SSL profile is configured with "Allow Dynamic Record Sizing" on a UDP virtual server, undisclosed traffic can cause the TMM process to terminate. The vulnerability was published on May 13, 2026, and affects BIG-IP versions 17.1.0 < 17.1.3.1, 17.5.0 < 17.5.1.4, 21.0.0 < 21.0.0.1, and 16.1.x (all versions); software versions that have reached End of Technical Support (EoTS) are not evaluated. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).
The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop), indicating that specially crafted network traffic triggers an unrecoverable loop condition within the TMM process, ultimately causing it to terminate. The attack vector is network-based, requiring no authentication, no user interaction, and no special privileges — only that the target BIG-IP device has a Client SSL profile with "Allow Dynamic Record Sizing" enabled on a UDP virtual server. The specific traffic pattern that triggers the condition has not been publicly disclosed by F5. No public proof-of-concept exploit code is known to exist at this time (GitHub Advisory, F5 Advisory).
Successful exploitation causes the TMM — the core data-plane process responsible for handling all traffic on F5 BIG-IP appliances — to terminate, resulting in a complete loss of availability for all services managed by the affected BIG-IP instance. There is no confidentiality or integrity impact; the attack is purely a Denial of Service. Depending on the deployment context, a TMM crash could disrupt load balancing, application delivery, and SSL/TLS termination for all downstream applications, potentially affecting large numbers of end users and critical business services (GitHub Advisory, F5 Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.072–0.098%, placing it in roughly the 27th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).
/var/log/tmm or /var/log/ltm; repeated TMM restart messages in BIG-IP system logs; core dump files generated in /var/core/ following TMM crashes.tmm process or rapid TMM restarts observable via tmsh show sys tmm-info or system monitoring dashboards.F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.1, 17.5.1.4, and 21.0.0.1. Organizations unable to upgrade immediately should disable "Allow Dynamic Record Sizing" on Client SSL profiles associated with UDP virtual servers if this feature is not operationally required. Additionally, implementing network-based access controls to restrict which sources can send traffic to affected UDP virtual servers can reduce exposure. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).
Coverage of CVE-2026-42920 has been limited to automated vulnerability tracking platforms and security aggregators such as VulDB, CVEFeed, and Eclypsium's May 2026 hardware fix summary. No notable independent researcher commentary or significant social media discussion has been identified. The vulnerability was detected by Tenable's Nessus scanner (plugin 316096), indicating it has been incorporated into standard vulnerability management tooling (Tenable Plugin, Eclypsium Summary).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."