
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-42920 is a Denial of Service vulnerability in F5 BIG-IP affecting the Traffic Management Microkernel (TMM). When a Client SSL profile is configured with "Allow Dynamic Record Sizing" on a UDP virtual server, undisclosed traffic can cause the TMM process to terminate. The vulnerability was published on May 13, 2026, and affects BIG-IP versions 17.1.0 < 17.1.3.1, 17.5.0 < 17.5.1.4, 21.0.0 < 21.0.0.1, and 16.1.x (all versions); software versions that have reached End of Technical Support (EoTS) are not evaluated. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).
The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop), indicating that specially crafted network traffic triggers an unrecoverable loop condition within the TMM process, ultimately causing it to terminate. The attack vector is network-based, requiring no authentication, no user interaction, and no special privileges — only that the target BIG-IP device has a Client SSL profile with "Allow Dynamic Record Sizing" enabled on a UDP virtual server. The specific traffic pattern that triggers the condition has not been publicly disclosed by F5. No public proof-of-concept exploit code is known to exist at this time (GitHub Advisory, F5 Advisory).
Successful exploitation causes the TMM — the core data-plane process responsible for handling all traffic on F5 BIG-IP appliances — to terminate, resulting in a complete loss of availability for all services managed by the affected BIG-IP instance. There is no confidentiality or integrity impact; the attack is purely a Denial of Service. Depending on the deployment context, a TMM crash could disrupt load balancing, application delivery, and SSL/TLS termination for all downstream applications, potentially affecting large numbers of end users and critical business services (GitHub Advisory, F5 Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.072–0.098%, placing it in roughly the 27th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).
/var/log/tmm or /var/log/ltm; repeated TMM restart messages in BIG-IP system logs; core dump files generated in /var/core/ following TMM crashes.tmm process or rapid TMM restarts observable via tmsh show sys tmm-info or system monitoring dashboards.F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.1, 17.5.1.4, and 21.0.0.1. Organizations unable to upgrade immediately should disable "Allow Dynamic Record Sizing" on Client SSL profiles associated with UDP virtual servers if this feature is not operationally required. Additionally, implementing network-based access controls to restrict which sources can send traffic to affected UDP virtual servers can reduce exposure. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).
Coverage of CVE-2026-42920 has been limited to automated vulnerability tracking platforms and security aggregators such as VulDB, CVEFeed, and Eclypsium's May 2026 hardware fix summary. No notable independent researcher commentary or significant social media discussion has been identified. The vulnerability was detected by Tenable's Nessus scanner (plugin 316096), indicating it has been incorporated into standard vulnerability management tooling (Tenable Plugin, Eclypsium Summary).
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"