Bug ID 1993737: [APM][SSO]TMM Core in the SSO decompress operation

Last Modified: Oct 17, 2025

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
17.5.0, 17.5.1, 17.5.1.2, 17.5.1.3

Opened: Jul 29, 2025

Severity: 3-Major

Symptoms

The TMM core backtrace shows a SIGSEGV in saml_sso_from_assigned_resources_and_profile, specifically a memcmp() call with a NULL meta_data pointer. The underlying issue appears to be a race condition or logic error where a decompress callback is triggered after the SSO state (metadata) has already been freed, possibly due to concurrent handling of decompress operations and redirect responses.

Impact

Traffic disrupted while tmm and apmd restarts.

Conditions

SAMl SSO is configured

Workaround

None

Fix Information

None

Behavior Change

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips