CVE-2025-54805: TMM Vulnerability
When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in the Traffic Management Microkernel (TMM) memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Other sources
When an iRule is configured on a virtual server via the declarative API, upon re-instantiation, the cleanup process can cause an increase in Traffic Management Microkernel (TMM) memory resource utilization.
— F5
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54805?
CVE-2025-54805 has a medium severity rating due to increased memory resource utilization affecting performance.
How do I fix CVE-2025-54805?
To fix CVE-2025-54805, upgrade to the recommended versions of F5 BIG-IP Next SPK, CNF, or for Kubernetes as specified in the advisory.
What products are affected by CVE-2025-54805?
CVE-2025-54805 affects F5 BIG-IP Next SPK and CNF versions between 1.1.0 and 2.0.0 as well as F5 BIG-IP Next for Kubernetes version 2.0.0.
What kind of issue does CVE-2025-54805 introduce?
CVE-2025-54805 introduces a memory resource utilization issue during the cleanup process after iRules are re-instantiated.
Is there a workaround for CVE-2025-54805?
Currently, there is no documented workaround for CVE-2025-54805, so upgrading to the fixed versions is advised.