First published: Wed May 07 2025(Updated: )
When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.
Credit: f5sirt@f5.com
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Next (LTM) | =20.2.0 | 20.2.1 |
F5 BIG-IP Next | ||
F5 BIG-IP Next | >=1.8.0<=1.9.2>=1.7.0<=1.7.11 | 1.7.12 |
F5 BIG-IP Next | ||
F5 BIG-IP Next | >=1.1.0<=1.2.1 | 1.3.0 |
F5 BIG-IP and BIG-IQ Centralized Management | =17.1.0 | 17.1.1 |
F5 BIG-IP and BIG-IQ Centralized Management | >=16.1.0<=16.1.3 | 16.1.4 |
F5 BIG-IP and BIG-IQ Centralized Management | >=15.1.0<=15.1.8 | 15.1.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2025-41399 is currently classified as high due to the potential for increased memory resource utilization.
To fix CVE-2025-41399, you should upgrade your F5 BIG-IP Next or other affected products to the latest recommended version as specified by F5.
CVE-2025-41399 affects multiple versions of F5 BIG-IP products, including those prior to certain fixed versions specified by F5.
CVE-2025-41399 may lead to excessive memory usage, potentially causing degradation of system performance or service interruptions.
F5 recommends applying the available patches as the primary solution, and no specific workarounds are provided for CVE-2025-41399.