QID 376774
Date Published: 2022-08-10
QID 376774: F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Linux kernel Vulnerability cve-2018-18281 (K36462841)
Since Linux kernel version 3.2, the mremap() syscall performs TLB flushes after dropping pagetable locks. If a syscall such as ftruncate() removes entries from the pagetables of a task that is in the middle of mremap(), a stale TLB entry can remain for a short time that permits access to a physical page after it has been released back to the page allocator and reused. This is fixed in the following kernel versions: 4.9.135, 4.14.78, 4.18.16, 4.19.CVE-2018-18281
Vulnerable Component: BIG-IP ASM,LTM,APM
Affected Versions:
16.1.0 - 16.1.2
15.1.0 - 15.1.5
14.1.0 - 14.1.4
13.1.0 - 13.1.4
QID Detection Logic(Authenticated):
This QID checks for the vulnerable versions of F5 BIG-IP devices using the tmsh command.
An attacker may be able to overflow temporary memory resources resulting in improper access to physical memory pages or denial-of-service (DoS).
- K36462841 -
support.f5.com/csp/article/K36462841
CVEs related to QID 376774
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| K36462841 |
|