CVE-2017-6166

Severity CVSS v4.0:
Pending analysis
Type:
CWE-415 Double Free
Publication date:
22/11/2017
Last modified:
20/04/2025

Description

In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, it will trigger a failover to the peer device.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:f5:big-ip_afm:*:*:*:*:*:*:*:* 12.0.0 (including) 12.1.1 (including)
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:* 12.0.0 (including) 12.1.1 (including)
cpe:2.3:a:f5:big-ip_apm:*:*:*:*:*:*:*:* 12.0.0 (including) 12.1.1 (including)
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:* 12.0.0 (including) 12.1.1 (including)
cpe:2.3:a:f5:big-ip_asm:*:*:*:*:*:*:*:* 12.0.0 (including) 12.1.1 (including)
cpe:2.3:a:f5:big-ip_dns:*:*:*:*:*:*:*:* 12.0.0 (including) 12.1.1 (including)
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:* 12.0.0 (including) 12.1.1 (including)
cpe:2.3:a:f5:big-ip_ltm:*:*:*:*:*:*:*:* 12.0.0 (including) 12.1.1 (including)
cpe:2.3:a:f5:big-ip_pem:*:*:*:*:*:*:*:* 12.0.0 (including) 12.1.1 (including)
cpe:2.3:a:f5:f5_websafe:*:*:*:*:*:*:*:* 12.0.0 (including) 12.1.1 (including)
cpe:2.3:a:f5:linerate:*:*:*:*:*:*:*:* 2.5.0 (including) 2.6.2 (including)