CVE-2025-61990
7.5F5 · BIG-IP
A double free vulnerability in F5 BIG-IP allows unauthenticated attackers to cause a Traffic Management Microkernel (TMM) termination by sending specific traffic to multi-bladed platforms.
Executive summary
A critical denial of service vulnerability in F5 BIG-IP allows unauthenticated remote attackers to crash the Traffic Management Microkernel, potentially disrupting all network traffic handled by the device.
Vulnerability
This issue is a double free vulnerability (CWE-415) triggered within the Traffic Management Microkernel when processing specific traffic on multi-bladed platforms. The vulnerability is network-exploitable by an unauthenticated attacker without requiring user interaction.
Business impact
The vulnerability carries a CVSS score of 7.5, reflecting a high impact on system availability. Successful exploitation results in the termination of the TMM, which effectively halts all traffic processing for the affected BIG-IP device. This can lead to significant service outages for critical business applications and infrastructure relying on the load balancer or security gateway.
Remediation
Immediate Action: Administrators must review the official F5 security advisory (K000156912) and apply the appropriate software updates for their specific BIG-IP platform and version.
Proactive Monitoring: Monitor system logs for repeated TMM restarts or high volumes of malformed traffic directed at the management or data planes of the BIG-IP system.
Compensating Controls: While no direct WAF mitigation is available for this kernel-level flaw, ensure that the management interface is restricted to trusted networks and that traffic filtering is applied at the network perimeter to minimize exposure.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for complete service disruption, organizations should prioritize patching affected F5 BIG-IP systems during the next maintenance window. The lack of authentication requirements makes this a highly accessible target for attackers, and immediate remediation is necessary to maintain infrastructure stability and prevent denial of service attacks.
More F5 CVEs
Sources
Originally found and disclosed by F5, per the CVE Program record.