CVE-2025-61938: BIG-IP Advanced WAF and ASM bd process vulnerability
When a BIG-IP Advanced WAF or ASM security policy is configured with a URL greater than 1024 characters in length for the Data Guard Protection Enforcement setting, either manually or through the automatic Policy Builder, the bd process can terminate repeatedly.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61938?
CVE-2025-61938 is considered a high severity vulnerability due to the potential for the bd process to repeatedly terminate, impacting system functionality.
How do I fix CVE-2025-61938?
To mitigate CVE-2025-61938, ensure that URL lengths in the Data Guard Protection Enforcement setting do not exceed 1024 characters.
What impact does CVE-2025-61938 have on BIG-IP Advanced WAF/ASM?
CVE-2025-61938 can cause repeated termination of the bd process, leading to service disruptions in the BIG-IP Advanced WAF/ASM.
Which versions of BIG-IP are affected by CVE-2025-61938?
CVE-2025-61938 affects F5 BIG-IP Advanced WAF/ASM versions 17.5.0 and versions in the 17.1.0 to 17.1.2 range.
Is there a workaround for CVE-2025-61938?
As a workaround for CVE-2025-61938, avoid configuring URL lengths greater than 1024 characters in the Data Guard Protection Enforcement setting.