Last Modified: May 09, 2025
Affected Product(s):
BIG-IP Install/Upgrade, TMOS
Known Affected Versions:
17.1.2, 17.1.2.1
Fixed In:
17.5.0
Opened: Jan 20, 2025 Severity: 2-Critical
REST tokens that are present in /var/run/pamcache on BIG-IP are not deleted after token expiration after the upgrade to version 17.1.2
More memory will be used as /run/pamcache is an in-memory filesystem Users who have requested 100+ REST tokens may start to receive 400 responses with the message: "user <username> has reached maximum active login tokens".
The system is upgraded to version 17.1.2
Manually remove expired tokens from /var/run/pamcache or delete them using the /mgmt/shared/authz/tokens API endpoint. Using clear-rest-storage will remove the tokens from REST storage as well as /var/run/pamcache
None