Information disclosure and TMM restart via memory leak
Published May 8, 2024 · Updated Feb 3, 2026
Memory buffer bounds errors in F5 BIG-IP tenants before 15.1.10 disclose random memory data and can restart a TMM. BIG-IP tenant TMMs on VELOS and rSeries can emit up to 64 bytes of non-contiguous randomized memory, with rare occurrences restarting the TMM. The event occurs randomly under unspecified conditions and cannot be deliberately triggered, limiting the impact to incidental disclosure and rare service interruption.
Summary
What happened
Memory buffer bounds errors in F5 BIG-IP tenants before 15.1.10 disclose random memory data and can restart a TMM. BIG-IP tenant TMMs on VELOS and rSeries can emit up to 64 bytes of non-contiguous randomized memory, with rare occurrences restarting the TMM. The event occurs randomly under unspecified conditions and cannot be deliberately triggered, limiting the impact to incidental disclosure and rare service interruption.
The record
- CVE
- CVE-2024-32761
- Published
- May 8, 2024
- Updated
- Feb 3, 2026
- Vendor
- F5 Networks
- Product
- BIG-IP
- Classifications
- CWE-119
- Attack vector
- network
- Privileges
- unauthenticated
Timeline
How it unfolded
- May 8, 2024CVE publishedPublication date reported by the CVE source.
- Feb 3, 2026Record updatedLatest update available in the CVE record.
Exploitability
Present is not the same as exploitable
Compare your product and version with the public record. A matching version still requires validation against your environment.
Is a vulnerable build present?
Compare these published version ranges with your installed build and any vendor patches.
- Affected versionversion=15.1.0
- Affected versionversion=15.1.0 <15.1.10
- Affected versionversion=16.1.0
- Affected versionversion=17.1.0
What conditions does exploitation require?
What is affected?
Published CVSS scores
CVSS describes severity. EPSS estimates exploitation probability.
Attacks
What attackers are doing with it
Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.
Weakness, pattern, technique
Public exploit references
No public exploit references are available in this record.
Labels summarize the accepted research assessment. They do not indicate a test against your environment.
Technologies
Your stack
See the directory against your own environment.
Your stack
Check the software in your environment
Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.
Book a demo