Bug ID 773821: Certain plaintext traffic may cause SSLO to hang

Last Modified: May 29, 2024

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
14.0.0, 14.0.0.1, 14.0.0.2, 14.0.0.3, 14.0.0.4, 14.0.0.5, 14.0.1, 14.0.1.1, 14.1.0, 14.1.0.1, 14.1.0.2, 14.1.0.3, 14.1.0.5, 14.1.0.6, 14.1.2, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2

Fixed In:
15.1.0, 15.0.1.3, 14.1.2.1

Opened: Apr 18, 2019

Severity: 3-Major

Symptoms

SSLO relies on SSL hudfilter to detect non-SSL traffic; but certain plaintext can be mistaken as SSL traffic, which can cause a hang.

Impact

SSLO hangs, unable to bypass traffic.

Conditions

Initial plaintext traffic resembles SSLv2 hello message or has less than enough bytes for SSL to process.

Workaround

None.

Fix Information

Improve SSL hello parser.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips