F5-K000140968: High severity f5 big-ip next vulnerability
Published May 7, 2025
·Updated
When HTTP/2 client and server profiles are simultaneously configured on a virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.
Affected Software
7 affected componentsFixes available
F5 BIG-IP Next SPK
2.0.0
F5 BIG-IP Next SPK>=1.8.0<=1.9.2, >=1.7.0<=1.7.8
1.7.9
F5 BIG-IP Next CNF
2.0.0
F5 BIG-IP Next CNF>=1.1.0<=1.3.3
1.4.0
F5 BIG-IP>=17.1.0<=17.1.1
17.1.2
F5 BIG-IP>=16.1.0<=16.1.4
16.1.5
F5 BIG-IP>=15.1.0<=15.1.10
-
Event History
May 7, 2025
Advisory Published
via F5·12:44 PM
Frequently Asked Questions
1
What is the severity of F5-K000140968?
The severity of F5-K000140968 is currently classified as critical due to the potential for service disruption.
2
How do I fix F5-K000140968?
To fix F5-K000140968, upgrade to the recommended fixes such as F5 BIG-IP Next SPK version 2.0.0 or relevant patched versions.
3
What are the symptoms of F5-K000140968?
Symptoms of F5-K000140968 include unexpected termination of the Traffic Management Microkernel when processing certain HTTP/2 requests.
4
Which products are affected by F5-K000140968?
F5-K000140968 affects several products including F5 BIG-IP Next SPK and F5 BIG-IP versions between 15.1.0 and 17.1.1.
5
Has a CVE been assigned to F5-K000140968?
As of now, F5-K000140968 does not have an associated CVE identifier.