Bug ID 1773213: OAuth core fail due to buffer overflow

Last Modified: Mar 12, 2025

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 15.1.0.5, 15.1.1, 15.1.2, 15.1.2.1, 15.1.3, 15.1.3.1, 15.1.4, 15.1.4.1, 15.1.5, 15.1.5.1, 15.1.6, 15.1.6.1, 15.1.7, 15.1.8, 15.1.8.1, 15.1.8.2, 15.1.9, 15.1.9.1, 15.1.10, 15.1.10.2, 15.1.10.3, 15.1.10.4, 15.1.10.5, 15.1.10.6

Opened: Dec 16, 2024

Severity: 3-Major

Symptoms

The SessionDB query result includes the additional columns (userinfo_claims, id_token_claim_data, and id_token_claims, oidc) which OAuth does not expect. This leads to memory corruption in the OAuth memory allocated to column lists, further causing an OAuth core to fail.

Impact

OAuth traffic is disrupted when OAuth restarts.

Conditions

OAuth is configured.

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips