Bug ID 1825513: ClientSSL profile with PQC group may cause TMM to crash

Last Modified: Aug 19, 2025

Affected Product(s):
BIG-IP LTM(all modules)

Known Affected Versions:
17.5.0

Fixed In:
17.5.1

Opened: Feb 28, 2025

Severity: 1-Blocking

Symptoms

TMM or system services may restart unexpectedly due to memory pressure. In /var/log/tmm: warning tmm[24255]: 01260013:4: SSL Handshake failed for TCP 10.20.2.115:44404 -> 10.20.40.191:443 err tmm[24255]: 01230140:3: RST sent from 10.20.40.191:443 to 10.20.2.115:44404, [0x3076761:2571] SSL handshake timeout exceeded err tmm3[24255]: 01010282:3: Crypto codec error: sw_crypto-3 RSA private encrypt error OpenSSL error:03078069:bignum routines:BN_EXPAND_INTERNAL:expand on static bignum data err tmm2[24255]: 01010282:3: Per-invocation log rate exceeded; throttling. err tmm6[24255]: 01010282:3: Resuming log processing at this invocation; held 53 messages.

Impact

Traffic disrupted while tmm restarts.

Conditions

Cipher rule DH group X25519KYBER768 is enabled.

Workaround

There is no workaround, disable X25519KYBER768 to mitigate the issue.

Fix Information

Fix memory issues.

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips