Threat reportVulnerabilityTL-2026-3274
F5 F5OS 2.0.0 Affected by Linux Kernel UDF Partition Descriptor Heap Out-of-Bounds Write (CVE-2026-45991)
F5 F5OS 2.0.0 Affected by Linux Kernel UDF Partition (TL-2026-3274) is a high-severity software vulnerability scored CVSS 7.8, first published 2026-10-10. It has no confirmed attribution, affects F5 F5OS, references 1 CVE (CVE-2026-45991), maps to 4 MITRE ATT&CK techniques (T1091, T1203, T1499.004), and is covered by 9 detection rules and 14 indicators of compromise.
- CVSS
- 7.8/10High
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 4MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 14Indicators of compromise
Key facts for TL-2026-3274
- Threat ID
- TL-2026-3274
- Severity
- HIGH
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, telecoms, government administration, finance, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 14
How F5 F5OS 2.0.0 Affected by Linux Kernel UDF Partition works
GovCERT.HK alert A26-10-09 reports that F5 F5OS 2.0.0 is affected by CVE-2026-45991, which could lead to tampering on an affected system. NVD describes CVE-2026-45991 as a heap out-of-bounds write in the Linux kernel UDF filesystem driver, triggered by mounting a crafted UDF image.
GovCERT.HK Security Alert A26-10-09 (published 2026-10-06) states that F5 F5OS version 2.0.0 is affected by CVE-2026-45991, that successful exploitation could lead to tampering on an affected system, and that vendor mitigations are available (F5 advisory K000163547). The F5 advisory page could not be retrieved during research (the myF5 portal returned a loading/error page), so the F5-specific impact statement, fixed versions and mitigations are unverified here and should be confirmed against K000163547.
Public records for CVE-2026-45991 identify it as a Linux kernel vulnerability, not an F5-specific code defect. The kernel CNA announcement (Greg Kroah-Hartman, 2026-05-27) and NVD describe a flaw in fs/udf/super.c: handle_partition_descriptor() deduplicates Partition Descriptors by partition number, but appended slots never record partnum. A crafted UDF image containing repeated Partition Descriptors therefore causes duplicate entries to be appended repeatedly, num_part_descs keeps growing, and a heap out-of-bounds write occurs in part_descs_loc[] while mounting. The defect was introduced in kernel 4.18.7 (commit 7f401f160a9c7a1ff84ba3cb9b2f636d1f5cfb6b). Upstream fixes: 6.6.140, 6.12.88, 7.0.4 and 7.1-rc1; NVD lists 5.10.259+, 5.15.210+ and 6.1.176+ as fixed as well. It is an inference, not a statement from the F5 source, that F5OS is affected because it ships an affected Linux kernel build.
NVD scores the issue CVSS 3.1 7.8 HIGH (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), CWE-787. Red Hat rates it Moderate (CVSS 6.6, AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), noting that exploitation requires mounting a malicious UDF filesystem, i.e. elevated privileges or physical access on systems configured to automount UDF volumes. Per the kernel announcement the impact is heap corruption (system instability, denial of service, potentially code execution). No source reviewed reports in-the-wild exploitation, a public PoC, a named threat actor, or network IOCs; CISA KEV was queried and CVE-2026-45991 was not found in the first portion of the feed read (the feed was only partially read). The IOC list below therefore contains vulnerability-specific artifacts (code locations, commits, products) usable for exposure assessment and hunting, not adversary infrastructure.
MITRE ATT&CK techniques used in TL-2026-3274
Initial Access
T1091 Replication Through Removable Media
Execution
T1203 Exploitation for Client Execution
Impact
T1499.004 Endpoint Denial of Service: Application or System Exploitation; T1565.001 Data Manipulation: Stored Data Manipulation
Affected products and versions in F5 F5OS 2.0.0 Affected by Linux Kernel UDF Partition
Remediation for F5 F5OS 2.0.0 Affected by Linux Kernel UDF Partition
Patches
- Apply the fixed F5OS release identified in F5 K000163547 (fixed version not verified in this research)
- Upstream kernel fix commits: 058b451b1039f056d1362c4fec2229e522366ab0 (6.6), b5597bb83fc37b5b5da74a4453fa920b932cf39a (6.12), 08fa5d818e5bf53c7ca234d88ba334f32004e9b6 (7.0), 08841b06fa64d8edbd1a21ca6e613420c90cc4b8 (7.1)
Immediate actions
- Review F5 advisory K000163547 and apply the vendor-provided mitigations for F5OS 2.0.0
- Restrict who can mount removable or image-based filesystems (UDF/optical/USB) on F5OS appliances and limit physical and administrative access
- Disable automounting of UDF volumes where it is configured
Workarounds
- Prevent mounting of untrusted UDF images (blacklist the udf kernel module where operationally possible)
Longer-term hardening
- Upgrade F5OS to a release whose kernel includes the upstream UDF fix (6.6.140, 6.12.88, 7.0.4, 7.1 or later branches) as specified by F5
- Monitor kernel logs for UDF mount errors and unexpected mount activity on network appliances
CVEs associated with F5 F5OS 2.0.0 Affected by Linux Kernel UDF Partition
Weaknesses (CWE) in F5 F5OS 2.0.0 Affected by Linux Kernel UDF Partition
Timeline of F5 F5OS 2.0.0 Affected by Linux Kernel UDF Partition
- NVD publishes the CVE-2026-45991 record with CVSS 3.1 7.8 HIGH (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), CWE-787.
- Linux kernel CNA (Greg Kroah-Hartman, linux-cve-announce) publishes CVE-2026-45991 (udf: fix partition descriptor heap out-of-bounds write) with fixes in 6.6.140, 6.12.88, 7.0.4 and 7.1-rc1.
- NVD record for CVE-2026-45991 last modified; fixed-version ranges extended to 5.10.259, 5.15.210 and 6.1.176 stable branches.
- GovCERT.HK cites F5 Security Advisory K000163547 as the vendor reference; the page content could not be retrieved during research.
- GovCERT.HK publishes Security Alert A26-10-09 stating F5OS 2.0.0 is affected by CVE-2026-45991, exploitation could lead to tampering, and vendor mitigations are available.
- TL-2026-3274 researched: no in-the-wild exploitation, public PoC, threat actor or network IOCs found in reviewed sources; F5-specific fixed versions remain to be confirmed from K000163547.
Sources cited for F5 F5OS 2.0.0 Affected by Linux Kernel UDF Partition
Detection coverage for TL-2026-3274
As of 2026-10-10, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3274 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.