CVE-2017-6166: Double Free
In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, it will trigger a failover to the peer device.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-6166?
CVE-2017-6166 is a vulnerability that affects BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software versions 12.0.0 to 12.1.1.
What is the severity of CVE-2017-6166?
The severity of CVE-2017-6166 is medium, with a severity value of 5.9.
How does CVE-2017-6166 affect the Traffic Management Microkernel (TMM)?
CVE-2017-6166 may cause the Traffic Management Microkernel (TMM) to crash when processing fragmented packets.
Which components are affected by CVE-2017-6166?
CVE-2017-6166 affects the following components: BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software versions 12.0.0 to 12.1.1.
Are there any known fixes for CVE-2017-6166?
Yes, F5 has released a patch to fix CVE-2017-6166. Please refer to the F5 support article for more information.