CVE-2026-42920: 
F5 BIG-IP Virtual Edition 脆弱性の分析と軽減

概要

CVE-2026-42920 is a Denial of Service vulnerability in F5 BIG-IP affecting the Traffic Management Microkernel (TMM). When a Client SSL profile is configured with "Allow Dynamic Record Sizing" on a UDP virtual server, undisclosed traffic can cause the TMM process to terminate. The vulnerability was published on May 13, 2026, and affects BIG-IP versions 17.1.0 < 17.1.3.1, 17.5.0 < 17.5.1.4, 21.0.0 < 21.0.0.1, and 16.1.x (all versions); software versions that have reached End of Technical Support (EoTS) are not evaluated. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, F5 Advisory).

技術的な詳細

The root cause is classified as CWE-835 (Loop with Unreachable Exit Condition / Infinite Loop), indicating that specially crafted network traffic triggers an unrecoverable loop condition within the TMM process, ultimately causing it to terminate. The attack vector is network-based, requiring no authentication, no user interaction, and no special privileges — only that the target BIG-IP device has a Client SSL profile with "Allow Dynamic Record Sizing" enabled on a UDP virtual server. The specific traffic pattern that triggers the condition has not been publicly disclosed by F5. No public proof-of-concept exploit code is known to exist at this time (GitHub Advisory, F5 Advisory).

影響

Successful exploitation causes the TMM — the core data-plane process responsible for handling all traffic on F5 BIG-IP appliances — to terminate, resulting in a complete loss of availability for all services managed by the affected BIG-IP instance. There is no confidentiality or integrity impact; the attack is purely a Denial of Service. Depending on the deployment context, a TMM crash could disrupt load balancing, application delivery, and SSL/TLS termination for all downstream applications, potentially affecting large numbers of end users and critical business services (GitHub Advisory, F5 Advisory).

エクスプロイト可能性

There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of publication. The EPSS score is approximately 0.072–0.098%, placing it in roughly the 27th percentile for exploitation likelihood within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory).

エクスプロイテーションのステップ

  1. Reconnaissance: Identify internet-facing F5 BIG-IP instances running affected versions (17.1.0 < 17.1.3.1, 17.5.0 < 17.5.1.4, 21.0.0 < 21.0.0.1, or 16.1.x) using tools such as Shodan or Censys, filtering for BIG-IP management interfaces or known service ports.
  2. Identify vulnerable configuration: Determine whether the target BIG-IP has a Client SSL profile with "Allow Dynamic Record Sizing" enabled on a UDP virtual server — this may be inferred from exposed service banners or configuration leakage.
  3. Send crafted UDP traffic: Transmit specially crafted (undisclosed) UDP traffic to the virtual server associated with the vulnerable Client SSL profile, designed to trigger the infinite loop condition in the TMM process.
  4. Achieve Denial of Service: The TMM process enters an unreachable exit condition (infinite loop) and terminates, causing all traffic handling on the BIG-IP device to cease and resulting in a service outage for all downstream applications (GitHub Advisory, F5 Advisory).

妥協の兆候

  • Logs: Unexpected TMM process termination events in /var/log/tmm or /var/log/ltm; repeated TMM restart messages in BIG-IP system logs; core dump files generated in /var/core/ following TMM crashes.
  • Process: Absence of the tmm process or rapid TMM restarts observable via tmsh show sys tmm-info or system monitoring dashboards.
  • Network: Unusual or malformed UDP traffic directed at virtual servers with Client SSL profiles configured with "Allow Dynamic Record Sizing"; traffic anomalies coinciding with TMM crashes.
  • System: BIG-IP failover events in HA pairs triggered by TMM unavailability; SNMP traps or alerts indicating TMM process failure.

軽減策と回避策

F5 has released patched versions addressing this vulnerability: BIG-IP 17.1.3.1, 17.5.1.4, and 21.0.0.1. Organizations unable to upgrade immediately should disable "Allow Dynamic Record Sizing" on Client SSL profiles associated with UDP virtual servers if this feature is not operationally required. Additionally, implementing network-based access controls to restrict which sources can send traffic to affected UDP virtual servers can reduce exposure. Upgrading to a patched version is the recommended long-term remediation (F5 Advisory, GitHub Advisory).

コミュニティの反応

Coverage of CVE-2026-42920 has been limited to automated vulnerability tracking platforms and security aggregators such as VulDB, CVEFeed, and Eclypsium's May 2026 hardware fix summary. No notable independent researcher commentary or significant social media discussion has been identified. The vulnerability was detected by Tenable's Nessus scanner (plugin 316096), indicating it has been incorporated into standard vulnerability management tooling (Tenable Plugin, Eclypsium Summary).

関連情報


ソース: このレポートは AI を使用して生成されました

関連 F5 BIG-IP Virtual Edition 脆弱 性:

CVE 識別子

重大度

スコア

テクノロジー

コンポーネント名

CISA KEV エクスプロイト

修正あり

公開日

CVE-2026-42920HIGH8.7
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-42930HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-42924HIGH8.5
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-42937HIGH7.1
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいMay 13, 2026
CVE-2026-63020LOW2.3
  • F5 BIG-IP Virtual Edition logoF5 BIG-IP Virtual Edition
  • cpe:2.3:a:f5:big-ip_access_policy_manager
いいえはいSep 02, 2026

無料の脆弱性評価

クラウドセキュリティポスチャーのベンチマーク

9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。

評価を依頼する

パーソナライズされたデモを見る

実際に Wiz を見てみませんか?​

"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
デビッド・エストリックCISO (最高情報責任者)
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
アダム・フレッチャーチーフ・セキュリティ・オフィサー
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"
グレッグ・ポニャトフスキ脅威および脆弱性管理責任者