CVE Vulnerabilities

CVE-2017-6166

Double Free

Published: Nov 22, 2017 | Modified: Dec 14, 2021
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

In BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, DNS, Link Controller, PEM, and WebSafe software 12.0.0 to 12.1.1, in some cases the Traffic Management Microkernel (TMM) may crash when processing fragmented packets. This vulnerability affects TMM through a virtual server configured with a FastL4 profile. Traffic processing is disrupted while TMM restarts. If the affected BIG-IP system is configured as part of a device group, it will trigger a failover to the peer device.

Weakness

The product calls free() twice on the same memory address, potentially leading to modification of unexpected memory locations.

Affected Software

Name Vendor Start Version End Version
Big-ip_afm F5 12.0.0 (including) 12.1.1 (including)
Big-ip_analytics F5 12.0.0 (including) 12.1.1 (including)
Big-ip_apm F5 12.0.0 (including) 12.1.1 (including)
Big-ip_application_acceleration_manager F5 12.0.0 (including) 12.1.1 (including)
Big-ip_asm F5 12.0.0 (including) 12.1.1 (including)
Big-ip_dns F5 12.0.0 (including) 12.1.1 (including)
Big-ip_link_controller F5 12.0.0 (including) 12.1.1 (including)
Big-ip_ltm F5 12.0.0 (including) 12.1.1 (including)
Big-ip_pem F5 12.0.0 (including) 12.1.1 (including)
F5_websafe F5 12.0.0 (including) 12.1.1 (including)
Linerate F5 2.5.0 (including) 2.6.2 (including)

Potential Mitigations

References