# F5 F5OS 2.0.0 Affected by Linux Kernel UDF Partition Descriptor Heap Out-of-Bounds Write (CVE-2026-45991)

> GovCERT.HK alert A26-10-09 reports that F5 F5OS 2.0.0 is affected by CVE-2026-45991, which could lead to tampering on an affected system. NVD describes CVE-2026-45991 as a heap out-of-bounds write in the Linux kernel UDF filesystem driver, triggered by mounting a crafted UDF image.

- **Published:** 2026-10-10T15:39:17Z
- **Last reviewed:** 2026-10-10T15:39:17Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3274
- **ID:** TL-2026-3274
- **Severity:** HIGH (CVSS 7.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-45991

## Description

GovCERT.HK Security Alert A26-10-09 (published 2026-10-06) states that F5 F5OS version 2.0.0 is affected by CVE-2026-45991, that successful exploitation could lead to tampering on an affected system, and that vendor mitigations are available (F5 advisory K000163547). The F5 advisory page could not be retrieved during research (the myF5 portal returned a loading/error page), so the F5-specific impact statement, fixed versions and mitigations are unverified here and should be confirmed against K000163547.

Public records for CVE-2026-45991 identify it as a Linux kernel vulnerability, not an F5-specific code defect. The kernel CNA announcement (Greg Kroah-Hartman, 2026-05-27) and NVD describe a flaw in fs/udf/super.c: handle_partition_descriptor() deduplicates Partition Descriptors by partition number, but appended slots never record partnum. A crafted UDF image containing repeated Partition Descriptors therefore causes duplicate entries to be appended repeatedly, num_part_descs keeps growing, and a heap out-of-bounds write occurs in part_descs_loc[] while mounting. The defect was introduced in kernel 4.18.7 (commit 7f401f160a9c7a1ff84ba3cb9b2f636d1f5cfb6b). Upstream fixes: 6.6.140, 6.12.88, 7.0.4 and 7.1-rc1; NVD lists 5.10.259+, 5.15.210+ and 6.1.176+ as fixed as well. It is an inference, not a statement from the F5 source, that F5OS is affected because it ships an affected Linux kernel build.

NVD scores the issue CVSS 3.1 7.8 HIGH (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), CWE-787. Red Hat rates it Moderate (CVSS 6.6, AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), noting that exploitation requires mounting a malicious UDF filesystem, i.e. elevated privileges or physical access on systems configured to automount UDF volumes. Per the kernel announcement the impact is heap corruption (system instability, denial of service, potentially code execution). No source reviewed reports in-the-wild exploitation, a public PoC, a named threat actor, or network IOCs; CISA KEV was queried and CVE-2026-45991 was not found in the first portion of the feed read (the feed was only partially read). The IOC list below therefore contains vulnerability-specific artifacts (code locations, commits, products) usable for exposure assessment and hunting, not adversary infrastructure.

## MITRE ATT&CK

- T1091 Replication Through Removable Media
- T1203 Exploitation for Client Execution
- T1499.004 Endpoint Denial of Service: Application or System Exploitation
- T1565.001 Data Manipulation: Stored Data Manipulation

## Sources

- [GovCERT.HK Security Alert (A26-10-09): Vulnerability in F5 F5OS](https://www.govcert.gov.hk/en/alerts_detail.php?id=2098)
- [F5 Security Advisory K000163547](https://my.f5.com/manage/s/article/K000163547)
- [CVE-2026-45991 (MITRE)](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-45991)
- [NVD CVE-2026-45991](https://nvd.nist.gov/vuln/detail/CVE-2026-45991)
- [linux-cve-announce: CVE-2026-45991 udf: fix partition descriptor heap out-of-bounds write](https://ratatoskr.run/linux-cve-announce/2026/05/17036791)
- [Red Hat CVE-2026-45991](https://access.redhat.com/security/cve/cve-2026-45991)
- [Red Hat Bugzilla 2482113 (CVE-2026-45991)](https://bugzilla.redhat.com/show_bug.cgi?id=2482113)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3274
