Bug ID 893281: Possible ssl stall on closed client handshake

Last Modified: Oct 16, 2023

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
14.1.2, 14.1.2.1, 14.1.2.2, 14.1.2.3, 14.1.2.4, 14.1.2.5, 14.1.2.6, 15.0.0, 15.0.1, 15.0.1.1, 15.0.1.2, 15.0.1.3, 15.0.1.4, 15.1.0, 15.1.0.1, 15.1.0.2, 15.1.0.3, 15.1.0.4, 16.0.0, 16.0.0.1, 16.0.1, 16.0.1.1, 16.0.1.2

Fixed In:
16.1.0, 15.1.0.5, 14.1.2.7

Opened: Mar 27, 2020

Severity: 3-Major

Symptoms

If a client connection closes before finishing client ssl handshake, in some cases BIG-IP ssl does not close and connection remains until idle timeout.

Impact

Some ssl client connection remain until idle timeout.

Conditions

Client ssl handshake and client FIN must arrive while BIG-IP server ssl finished is in crypto.

Workaround

None

Fix Information

Allow transmit of any pending crypto during ssl shutdown.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips