F5-K000140919: High severity f5 big-ip next (ltm) vulnerability
Published May 7, 2025
·Updated
When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization.
Affected Software
8 affected componentsFixes available
F5 BIG-IP Next>=20.2.0<=20.2.1
20.3.0
F5 BIG-IP Next SPK
2.0.0
F5 BIG-IP Next SPK>=1.7.0<=1.9.2
F5 BIG-IP Next CNF
2.0.0
F5 BIG-IP Next CNF>=1.1.0<=1.4.1
F5 BIG-IP>=17.1.0<=17.1.1
17.1.2
F5 BIG-IP>=16.1.0<=16.1.5
16.1.6
F5 BIG-IP
Event History
May 7, 2025
Advisory Published
via F5·01:01 PM
Frequently Asked Questions
1
What is the severity of F5-K000140919?
The severity of F5-K000140919 is categorized as medium, indicating a potential risk of increased memory resource utilization.
2
How do I fix F5-K000140919?
To fix F5-K000140919, upgrade your BIG-IP and BIG-IP Next to the recommended version indicated in the advisory.
3
What products are affected by F5-K000140919?
F5-K000140919 affects various versions of F5 BIG-IP, BIG-IP Next, and related profiles configured with HTTP/2 httprouter.
4
What are the symptoms of F5-K000140919?
Symptoms of F5-K000140919 include unexpected increased memory resource utilization when handling requests.
5
Is there a workaround for F5-K000140919?
Currently, no official workaround is recommended for F5-K000140919 other than applying the necessary software updates.