F5-K000156994: Buffer Overflow
Published Oct 14, 2025
·Updated
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION6RD parsing.
Affected Software
4 affected componentsFixes available
F5 BIG-IP>=17.5.0<=17.5.1, >=17.1.0<=17.1.3
F5 BIG-IP>=16.1.0<=16.1.6
F5 BIG-IP>=15.1.0<=15.1.10
F5 F5OS-A>=1.8.0<=1.8.3, >=1.5.1<=1.5.4
1.8.4
Event History
Oct 14, 2025
Advisory Published
via F5·02:46 AM
Data Sourced
via F5·02:46 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of F5-K000156994?
The severity of F5-K000156994 is considered high due to the potential for remote code execution.
2
How do I fix F5-K000156994?
To fix F5-K000156994, upgrade BusyBox to version 1.25.0 or later.
3
Which F5 BIG-IP versions are affected by F5-K000156994?
F5-K000156994 affects F5 BIG-IP versions 17.5.0 to 17.5.1, 17.1.0 to 17.1.3, 16.1.0 to 16.1.6, and 15.1.0 to 15.1.10.
4
What impact does F5-K000156994 have?
F5-K000156994 can allow remote attackers to exploit a heap-based buffer overflow in the DHCP client.
5
Is there a workaround for F5-K000156994?
There are no known workarounds for F5-K000156994; applying the patch is recommended.