Bug ID 723794: PTI (Meltdown) mitigation should be disabled on AMD-based platforms

Last Modified: Jul 12, 2023

Affected Product(s):
BIG-IP All(all modules)

Known Affected Versions:
13.1.1.4, 13.1.1.3, 13.1.1.2, 13.1.1, 13.1.0.8, 13.1.0.7, 13.1.0.6, 13.1.0.5, 13.1.0.4, 13.0.1, 12.1.4, 12.1.3.7, 12.1.3.6, 12.1.3.5, 12.1.3.4, 12.1.3.3, 11.6.4, 11.6.3.3, 11.6.3.2, 11.6.3.1, 11.5.9, 11.5.8, 11.5.7, 11.5.6, 11.5.10

Fixed In:
13.1.1.5, 12.1.4.1, 11.6.5.1

Opened: Jun 11, 2018

Severity: 3-Major

Symptoms

Platforms with AMD processors freeze when the PTI (Page Table Isolation) mitigation is enabled, after a period ranging from several hours to several days. You can find information about which versions have the PTI (Meltdown) mitigations enabled in the AskF5 Article: Bug ID 707226: DB variables to disable CVE-2017-5754 Meltdown/PTI mitigations :: https://cdn.f5.com/product/bugtracker/ID707226.html.

Impact

System locks up and is rebooted by the watchdog timer.

Conditions

-- AMD-based platforms: + BIG-IP B4100 blades + BIG-IP B4200 blades + BIG-IP 6900 and NEBS appliances + BIG-IP 89x0 appliances + BIG-IP 6400 FIPS and NEBS platforms + BIG-IP 110x0 appliances -- The database variable kernel.pti is set to enable (to address PTI (Meltdown)).

Workaround

Set the database variable kernel.pti to disable by running the following command: tmsh modify sys db kernel.pti value disable According to AMD, these AMD processors are not vulnerable to PTI (Meltdown), so there is no reason to leave the db variable enabled.

Fix Information

PTI (Page Table Isolation) mitigation is no longer enabled on AMD-based platforms.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips