F5-K000140222: Race Condition
A security regressionwas discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote attacker may be able to trigger it by failing to authenticate within a set time period.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000140222?
The severity of F5-K000140222 is considered moderate due to the potential impact of a race condition in the OpenSSH server.
How do I fix F5-K000140222?
To fix F5-K000140222, upgrade your affected F5 products to the latest versions as specified in the advisory.
What products are affected by F5-K000140222?
F5-K000140222 affects F5 BIG-IP Next, F5 BIG-IP Next Central Manager, F5 BIG-IP Next SPK, and F5 BIG-IP Next CNF within specified version ranges.
How can an attacker exploit F5-K000140222?
An attacker can exploit F5-K000140222 by failing to authenticate within the set time period, leading to a race condition in the sshd process.
Is there a workaround for F5-K000140222?
Currently, the recommended action for F5-K000140222 is to apply the available patch rather than relying on workarounds.