SB2026051432 - Remote denial of service in BIG-IP DTLS
Published: May 14, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Infinite loop (CVE-ID: CVE-2026-42920)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to loop with unreachable exit condition in the Client SSL profile when processing undisclosed traffic on a UDP virtual server with Allow Dynamic Record Sizing enabled. A remote attacker can send traffic to cause a denial of service.
Only the data plane is exposed; there is no control plane exposure. Traffic is disrupted while the TMM process restarts.
Remediation
Install update from vendor's website.