F5-K000160086: High severity F5 Traffix SDC vulnerability
In the Linux kernel, the following vulnerability has been resolved: tls: separate no-async decryption request handling from async If we're not doing async, the handling is much simpler. There's no reference counting, we just need to wait for the completion to wake us up and return its result. We should preferably also use a separate cryptowait. I'm not seeing a UAF as I did in the past, I think aec7961916f3 ("tls: fix race between async notify and socket close") took care of it. This will make the next fix easier.
Affected Software
Event History
Frequently Asked Questions
What is the severity of F5-K000160086?
The severity of F5-K000160086 is categorized as high due to potential exploitation risks in the Linux kernel.
How do I fix F5-K000160086?
To fix F5-K000160086, upgrade your F5 Traffix SDC software to version 5.2.1 or later.
What systems are affected by F5-K000160086?
F5-K000160086 affects the F5 Traffix SDC software version 5.2.0.
What exploit capabilities are associated with F5-K000160086?
F5-K000160086 may allow an attacker to bypass security mechanisms related to asynchronous decryption processes.
Is there a workaround for F5-K000160086 if I cannot update immediately?
There are currently no official workarounds for F5-K000160086, and it's recommended to apply the patch as soon as possible.