CVE-2022-23012: Double Free
On BIG-IP versions 15.1.x before 15.1.4.1 and 14.1.x before 14.1.4.5, when the HTTP/2 profile is configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-23012?
The severity of CVE-2022-23012 is classified as critical due to its potential impact on the Traffic Management Microkernel.
How do I fix CVE-2022-23012?
To fix CVE-2022-23012, upgrade to BIG-IP versions 15.1.4.1 or 14.1.4.5 or later.
Which versions are affected by CVE-2022-23012?
CVE-2022-23012 affects BIG-IP versions 15.1.x prior to 15.1.4.1 and 14.1.x prior to 14.1.4.5.
What components are vulnerable in CVE-2022-23012?
The components vulnerable to CVE-2022-23012 include F5 BIG-IP Access Policy Manager, Advanced Firewall Manager, and Local Traffic Manager among others.
Can undisclosed requests trigger issues in CVE-2022-23012?
Yes, undisclosed requests can cause the Traffic Management Microkernel to terminate as noted in CVE-2022-23012.