Bug ID 701737: apmd may leak memory on destroying Kerberos cache

Last Modified: Jul 12, 2023

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
13.0.0, 13.0.0 HF1, 13.0.0 HF2, 13.0.0 HF3, 13.0.1, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3

Fixed In:
14.0.0, 13.1.0.4

Opened: Jan 12, 2018

Severity: 3-Major

Symptoms

ampd leaks memory in AD Query agent.

Impact

The ampd leaks memory and might cause unstable behavior. The apmd process, or some other daemon may be killed by OOM killer when it tries to allocate memory.

Conditions

The leak happens in response to any of the following conditions: -- A Kerberos cache reset is requested (any of the caches - GROUP/PSO/KERBEROS). -- Change to associated AAA AD Server were made and new Access Policy is applied. -- AD Query was not able to make ldap_bind to KDC and the error is NOT a timeout (e.g., invalid administrator password).

Workaround

There is no workaround at this time.

Fix Information

AD Query agent no longer causes apmd memory leak during group cache update.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips