Infinite loop in BIG-IP - CVE-2026-42920
Published: May 14, 2026
BIG-IP
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to loop with unreachable exit condition in the Client SSL profile when processing undisclosed traffic on a UDP virtual server with Allow Dynamic Record Sizing enabled. A remote attacker can send traffic to cause a denial of service.
Only the data plane is exposed; there is no control plane exposure. Traffic is disrupted while the TMM process restarts.