PT-2026-40641 · F5 · Big-Ip

Published

2026-05-13

·

Updated

2026-05-17

·

CVE-2026-39458

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP versions prior to 17.1.3.2 F5 BIG-IP versions prior to 17.5.1.6 F5 BIG-IP versions prior to 21.0.0.1
Description An uninitialized pointer in the Traffic Management Microkernel (TMM) can be triggered by undisclosed traffic when a BIG-IP DNS profile with DNS cache enabled is configured on a virtual server. This can lead to the termination of the TMM.
Recommendations Update to version 17.1.3.2 or later. Update to version 17.5.1.6 or later. Update to version 21.0.0.1 or later.

Fix

Access of Uninitialized Pointer

Weakness Enumeration

Related Identifiers

CVE-2026-39458

Affected Products

Big-Ip