CVE-2025-59781

7.5

F5 · BIG-IP and BIG-IP Next CNF

A memory resource exhaustion vulnerability exists in F5 BIG-IP and BIG-IP Next CNF when DNS cache is configured, potentially caused by undisclosed DNS queries.

Executive summary

A high-severity memory exhaustion vulnerability in F5 BIG-IP products allows unauthenticated attackers to potentially disrupt services by sending specific DNS queries.

Vulnerability

This is an incomplete cleanup vulnerability (CWE-459) where specific DNS queries trigger increased memory utilization on devices with DNS cache configured. The vulnerability is network-accessible and requires no authentication for an attacker to trigger the condition.

Business impact

Successful exploitation of this vulnerability leads to increased memory consumption, which can result in a denial-of-service condition for the affected BIG-IP infrastructure. Given the CVSS score of 7.5, this flaw represents a significant availability risk for organizations relying on these devices for traffic management and security. Service disruption could lead to extended downtime for critical business applications that depend on the availability of the BIG-IP load balancing and DNS services.

Remediation

Immediate Action: Upgrade to the patched versions as specified in the F5 security advisory K000150637 (BIG-IP 17.5.0 or later, and BIG-IP Next CNF 2.0.0 or later).

Proactive Monitoring: Monitor system memory utilization and DNS cache performance metrics to identify potential spikes indicative of exploitation attempts.

Compensating Controls: Implement rate limiting or Access Control Lists (ACLs) on the BIG-IP device to restrict the sources permitted to send DNS queries to the virtual server.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should prioritize the assessment of their F5 BIG-IP inventory to identify vulnerable instances. Given the potential for service degradation, administrators are strongly advised to apply the vendor-provided updates during the next maintenance window to ensure system stability and availability.

More F5 CVEs

Sources

Originally found and disclosed by F5, per the CVE Program record.