QID 376034
Date Published: 2021-12-20
QID 376034: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Linux kernel Vulnerability (K01512680)
An issue was discovered in the Linux kernel before 5.0.4. There is a use-after-free upon attempted read access to /proc/ioports after the ipmi_si module is removed, related to drivers/char/ipmi/ipmi_si_intf.c, drivers/char/ipmi/ipmi_si_mem_io.c, and drivers/char/ipmi/ipmi_si_port_io.c.CVE-2019-11811
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
16.1.016.0.0 - 16.0.1
15.0.0 - 15.1.3
14.0.0 - 14.1.4
13.1.0 - 13.1.1
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker, with local access to read /proc/ioports, may be able to create a use-after-free condition when the kernel module is unloaded, which may result in privilege escalation.
Solution
The vendor has released patch, for more information please visit: K01512680
Vendor References
- K01512680 -
support.f5.com/csp/article/K01512680
CVEs related to QID 376034
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K01512680 |
|