Cloud-Native Network Functions on Robin.io 2.2.2 release notes

About this release

Introduction

These release notes describe the differences between CNFs on Robin.io 2.2.1 and 2.2.2.

Supported container-orchestration platforms

This release is officially supported on these container-orchestration platforms and versions:

Platform Version Recommended Helm version
Robin.io 5.4.3-616 3 or later
Robin.io 5.4.3-564 3 or later
Robin.io 5.4.3-302 3 or later
Robin.io 5.3.11-217 3 or later

Security updates

This section lists the F5 vulnerability bugs of this release.

CVE Number Bug IDs Image Names Package Name
CVE-2016-2781 2160477 BaseOS coreutils
CVE-2022-3219 2160481, 2226573 BaseOS gpgv
CVE-2025-0167 2159613, 2159849, 2159873, 2160293, 2226457, 2226653 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img curl, libcurl4t64
CVE-2025-10148 2159617, 2159853, 2159877, 2160297, 2226657 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img curl, libcurl4t64
CVE-2025-14017 2227153, 2231521, 2231525, 2231533 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress curl, libcurl4t64
CVE-2025-14524 2226461, 2226505, 2226601, 2226661, 2226709 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img curl, libcurl4t64
CVE-2025-14819 2226465, 2226509, 2226605, 2226665, 2226713 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img curl, libcurl4t64
CVE-2025-14831 2226737 baseos libgnutls30t64
CVE-2025-15079 2226469, 2226513, 2226609, 2226669, 2226717 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img curl, libcurl4t64
CVE-2025-15224 2226473, 2226517, 2226613, 2226673, 2226721 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img curl, libcurl4t64
CVE-2025-5278 2251717 baseos coreutils
CVE-2025-6141 2251721 baseos libncursesw6
CVE-2025-61984 2226549 gslb-engine openssh-client
CVE-2025-61985 2226553 gslb-engine openssh-client
CVE-2025-68121 2225665, 2226213, 2226233 f5-dssm-upgrader, vault, vault-init stdlib
CVE-2025-68972 2226569, 2226741 baseos, rabbit dirmngr, gpgv
CVE-2025-70873 2266997 postgresql sqlite-libs
CVE-2025-8277 2226477, 2226725 f5-debug-sidecar, f5-fluentbit libssh-4
CVE-2025-8941 2160473 baseos libpam-modules
CVE-2025-9086 2159621, 2159857, 2159881, 2179697, 2226681 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img curl, libcurl4t64
CVE-2025-9820 2231537 baseos libgnutls30t64
CVE-2026-0964 2226441, 2226697 f5-debug-sidecar, f5-fluentbit libssh-4
CVE-2026-0965 2226481, 2226729 f5-debug-sidecar, f5-fluentbit libssh-4
CVE-2026-0966 2226485, 2226733 f5-debug-sidecar, f5-fluentbit libssh-4
CVE-2026-0967 2226445, 2226701 f5-debug-sidecar, f5-fluentbit libssh-4
CVE-2026-0968 2226449, 2226705 f5-debug-sidecar, f5-fluentbit libssh-4
CVE-2026-0994 2231529 f5-l4p-engine libprotobuf32t64
CVE-2026-1229 2231185, 2231237 vault, vault-init github.com/cloudflare/circl
CVE-2026-1519 2267513 f5-debug-sidecar bind9-dnsutils
CVE-2026-1965 2242005, 2242021, 2242037, 2242053, 2242077, 2260557 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img, postgresql curl, libcurl4t64
CVE-2026-2003 2227165 f5-fluentbit libpq5
CVE-2026-2004 2227169 f5-fluentbit libpq5
CVE-2026-2005 2227173 f5-fluentbit libpq5
CVE-2026-2006 2227177 f5-fluentbit libpq5
CVE-2026-22184 2231173, 2231225 vault, vault-init zlib
CVE-2026-24051 2230977, 2231005, 2231177, 2231229 cert-manager-controller, cert-manager-webhook, vault, vault-init go.opentelemetry.io/otel/sdk
CVE-2026-24515 2226533, 2226557 dnsx-img, spk-csrc libexpat1
CVE-2026-25210 2226537, 2226561 dnsx-img, spk-csrc libexpat1
CVE-2026-25679 2230893, 2230905, 2230909, 2230913, 2230917, 2230921, 2230965, 2230981, 2230993, 2231009, 2231021, 2231033, 2231045, 2231057, 2231069, 2231081, 2231101, 2231113, 2231125, 2231137, 2231149, 2231161, 2231189, 2231201, 2231213, 2231241, 2231253, 2231265, 2231277, 2231289, 2231301, 2231313, 2231325, 2231337, 2231349, 2231361, 2231373, 2231385, 2231397, 2231409, 2231421, 2231433, 2231445, 2231457, 2231469, 2231481, 2231493, 2231505, 2231541, 2241981, 2241985, 2260445, 2266097, 2266949 baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init stdlib
CVE-2026-2673 2251709, 2266817 baseos, vault-init libcrypto3, libssl3t64
CVE-2026-26958 2225733, 2226301, 2226437 opentelemetry-collector-contri, vault, vault-init filippo.io/edwards25519
CVE-2026-27137 2231085, 2231749 f5-csm-qkview, opentelemetry-collector-contri stdlib
CVE-2026-27138 2231089, 2231753 f5-csm-qkview, opentelemetry-collector-contri stdlib
CVE-2026-27139 2230897, 2230925, 2230929, 2230933, 2230937, 2230941, 2230969, 2230985, 2230997, 2231013, 2231025, 2231037, 2231049, 2231061, 2231073, 2231093, 2231105, 2231117, 2231129, 2231141, 2231153, 2231165, 2231193, 2231205, 2231217, 2231245, 2231257, 2231269, 2231281, 2231293, 2231305, 2231317, 2231329, 2231341, 2231353, 2231365, 2231377, 2231389, 2231401, 2231413, 2231425, 2231437, 2231449, 2231461, 2231473, 2231485, 2231497, 2231509, 2231545, 2241997, 2242001, 2260453, 2266209, 2266981 baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init stdlib
CVE-2026-27142 2230901, 2230945, 2230949, 2230953, 2230957, 2230961, 2230973, 2230989, 2231001, 2231017, 2231029, 2231041, 2231053, 2231065, 2231077, 2231097, 2231109, 2231121, 2231133, 2231145, 2231157, 2231169, 2231197, 2231209, 2231221, 2231249, 2231261, 2231273, 2231285, 2231297, 2231309, 2231321, 2231333, 2231345, 2231357, 2231369, 2231381, 2231393, 2231405, 2231417, 2231429, 2231441, 2231453, 2231465, 2231477, 2231489, 2231501, 2231513, 2231549, 2241989, 2241993, 2260449, 2266145, 2266965 baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init stdlib
CVE-2026-27171 2231181, 2231233, 2251725 baseos, vault, vault-init zlib, zlib1g
CVE-2026-2781 2266989 postgresql nss-libs
CVE-2026-27820 2231517 f5-fluentd zlib
CVE-2026-28387 2266821, 2267001, 2267577 baseos, postgresql, vault-init libcrypto3, libssl3t64, openssl
CVE-2026-28388 2266785, 2267005, 2267581 baseos, postgresql, vault-init libcrypto3, libssl3t64, openssl
CVE-2026-28389 2266789, 2267009, 2267585 baseos, postgresql, vault-init libcrypto3, libssl3t64, openssl
CVE-2026-28390 2266765, 2267013, 2267589 baseos, postgresql, vault-init libcrypto3, libssl3t64, openssl
CVE-2026-29111 2267545, 2267557 baseos, f5-fluentd libsystemd-shared, libsystemd0
CVE-2026-31789 2266825, 2267017, 2267593 baseos, postgresql, vault-init libcrypto3, libssl3t64, openssl
CVE-2026-31790 2266793, 2267021, 2267561 baseos, postgresql, vault-init libcrypto3, libssl3t64, openssl
CVE-2026-32280 2266069, 2266101, 2266105, 2266109, 2266113, 2266117, 2266233, 2266257, 2266289, 2266321, 2266349, 2266373, 2266397, 2266421, 2266445, 2266493, 2266517, 2266545, 2266569, 2266593, 2266617, 2266645, 2266717, 2266741, 2266769, 2266841, 2266865, 2266893, 2266921, 2266953, 2267029, 2267057, 2267081, 2267105, 2267133, 2267157, 2267185, 2267209, 2267233, 2267257, 2267281, 2267309, 2267333, 2267357, 2267381, 2267405, 2267429, 2267457, 2267485, 2267549 baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init stdlib
CVE-2026-32281 2266081, 2266149, 2266153, 2266157, 2266161, 2266165, 2266241, 2266273, 2266301, 2266333, 2266357, 2266381, 2266405, 2266429, 2266461, 2266501, 2266525, 2266553, 2266577, 2266601, 2266625, 2266673, 2266725, 2266749, 2266797, 2266849, 2266877, 2266905, 2266929, 2266969, 2267041, 2267065, 2267089, 2267117, 2267141, 2267169, 2267193, 2267217, 2267241, 2267265, 2267293, 2267317, 2267341, 2267365, 2267389, 2267413, 2267441, 2267465, 2267493, 2267565 baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init stdlib
CVE-2026-32282 2266073, 2266121, 2266125, 2266129, 2266133, 2266137, 2266237, 2266261, 2266293, 2266325, 2266353, 2266377, 2266401, 2266425, 2266449, 2266497, 2266521, 2266549, 2266573, 2266597, 2266621, 2266649, 2266721, 2266745, 2266773, 2266845, 2266869, 2266897, 2266925, 2266961, 2267033, 2267061, 2267085, 2267109, 2267137, 2267161, 2267189, 2267213, 2267237, 2267261, 2267285, 2267313, 2267337, 2267361, 2267385, 2267409, 2267433, 2267461, 2267489, 2267553 baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init stdlib
CVE-2026-32283 2266093, 2266213, 2266217, 2266221, 2266225, 2266229, 2266253, 2266285, 2266317, 2266345, 2266369, 2266393, 2266417, 2266441, 2266485, 2266513, 2266541, 2266565, 2266589, 2266613, 2266637, 2266705, 2266737, 2266761, 2266829, 2266861, 2266889, 2266917, 2266941, 2266985, 2267053, 2267077, 2267101, 2267129, 2267153, 2267181, 2267205, 2267229, 2267253, 2267277, 2267305, 2267329, 2267353, 2267377, 2267401, 2267425, 2267453, 2267481, 2267509, 2267597 baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init stdlib
CVE-2026-32285 2260485 opentelemetry-collector-contri github.com/buger/jsonparser
CVE-2026-32286 2260517, 2260537, 2260593 f5-license-proxy, vault, vault-init github.com/jackc/pgproto3/v2
CVE-2026-32287 2260489 opentelemetry-collector-contri github.com/antchfx/xpath
CVE-2026-32288 2266085, 2266169, 2266173, 2266177, 2266181, 2266185, 2266245, 2266277, 2266305, 2266337, 2266361, 2266385, 2266409, 2266433, 2266465, 2266505, 2266529, 2266557, 2266581, 2266605, 2266629, 2266677, 2266729, 2266753, 2266801, 2266853, 2266881, 2266909, 2266933, 2266973, 2267045, 2267069, 2267093, 2267121, 2267145, 2267173, 2267197, 2267221, 2267245, 2267269, 2267297, 2267321, 2267345, 2267369, 2267393, 2267417, 2267445, 2267469, 2267497, 2267569 baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init stdlib
CVE-2026-32289 2266089, 2266189, 2266193, 2266197, 2266201, 2266205, 2266249, 2266281, 2266309, 2266341, 2266365, 2266389, 2266413, 2266437, 2266469, 2266509, 2266533, 2266561, 2266585, 2266609, 2266633, 2266681, 2266733, 2266757, 2266805, 2266857, 2266885, 2266913, 2266937, 2266977, 2267049, 2267073, 2267097, 2267125, 2267149, 2267177, 2267201, 2267225, 2267249, 2267273, 2267301, 2267325, 2267349, 2267373, 2267397, 2267421, 2267449, 2267473, 2267501, 2267573 baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init stdlib
CVE-2026-33186 2260425, 2260429, 2260433, 2260437, 2260441, 2260457, 2260461, 2260465, 2260469, 2260473, 2260481, 2260501, 2260505, 2260509, 2260513, 2260529, 2260533, 2260549, 2260569, 2260573, 2260577, 2260581, 2260585, 2260589, 2260597, 2260601, 2260605, 2260609, 2260613, 2266945 cert-manager-controller, cert-manager-webhook, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dwbld, f5-fluentd, f5-fqdn-resolver, f5-l4p-engine, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, ocnos-img, opentelemetry-collector-contri, spk-csrc, spk-cwc, vault, vault-init google.golang.org/grpc
CVE-2026-33210 2260617 f5-fluentd json
CVE-2026-33810 2266489 opentelemetry-collector-contri stdlib
CVE-2026-33997 2260497, 2260525, 2260545 opentelemetry-collector-contri, vault, vault-init github.com/docker/docker
CVE-2026-34040 2260493, 2260521, 2260541 opentelemetry-collector-contri, vault, vault-init github.com/docker/docker
CVE-2026-3497 2242073 gslb-engine openssh-client
CVE-2026-34986 2266077, 2266141, 2266265, 2266297, 2266453, 2266653, 2266777, 2266873, 2266901, 2267037, 2267113, 2267165, 2267289, 2267437 cert-manager-controller, crd-conversion, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-license-helper, f5-license-proxy, f5-toda-observer, f5ing-tmm-pod-manager, f5ingress, opentelemetry-collector-contri, spk-cwc, vault, vault-init github.com/go-jose/go-jose/v3, github.com/go-jose/go-jose/v4
CVE-2026-35206 2267477 f5-lifecycle-operator helm.sh/helm/v3
CVE-2026-3731 2242009, 2242025, 2242041, 2242057, 2242081 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img libssh-4
CVE-2026-3783 2242013, 2242029, 2242045, 2242061, 2242085, 2260561 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img, postgresql curl, libcurl4t64
CVE-2026-3784 2242017, 2242033, 2242049, 2242065, 2242089, 2260565 crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img, postgresql curl, libcurl4t64
CVE-2026-3805 2260553 postgresql curl
CVE-2026-39882 2266473 opentelemetry-collector-contri go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp
CVE-2026-39883 2266269, 2266329, 2266457, 2266657, 2266781 cert-manager-controller, cert-manager-webhook, opentelemetry-collector-contri, vault, vault-init go.opentelemetry.io/otel/sdk
CVE-2026-40179 2266313, 2266537, 2267505 f5-coremond, f5-csm-qkview, f5-fluentd github.com/prometheus/prometheus
CVE-2026-40200 2266833 vault-init musl
CVE-2026-4105 2251713 baseos libsystemd0
CVE-2026-4437 2267025 postgresql glibc
CVE-2026-4438 2266993 postgresql glibc
CVE-2026-4878 2266685, 2266809 vault, vault-init libcap
CVE-2026-6042 2266837 vault-init musl

New features

(No new features)

Enhancements

(No new enhancements)

Model changes

(No model changes)

Fixed issues

2263137-1

Title: Path-slice extraction on long URIs may cause TMM exit

Component: fsm-hudfilters

Symptoms: TMM can crash when a request’s URI path exceeds the xbuf MSS and a rule compares a path slice (a subsection of the URI path).

Conditions: When an administrator configures an iRule, ServiceBasedInterface static route, or TDR filter to compare a URI path “slice” (subsection) and the path exceeds the MSS, issues can occur. A slice is specified with the Path pseudo-header (:p) plus the slash-delimited segment range; for example, :p:s3-5 selects the 3rd–5th path segments.

Impact: Incorrect code branch causes TMM termination.

Mitigation / Workaround: N/A

Fix Text: Path-slice comparisons behave correctly for any URI path length.

2221753-1

Title: F5BigCneDatagroup configuration fails for non-address data types

Component: CRD

Symptoms: Datagroup configuration with “recordType: string” or “recordType: integer” fails with schema validation errors such as the following, preventing valid configurations.

  • : Invalid value: “”: “spec.records[0].key” must validate one and only one schema (oneOf). Found none valid.

Conditions: The Datagroup data type is specified via the “recordType” setting, which can be set to “address,” “integer,” or “string”. However for all datatypes, the CRD schema validation wrongly enforces IP Address validation, preventing “string” & “integer” data type configs to always fail.

Impact: Datagroup supports only the IP Address recordType and does not support the “integer” & “string” types.

Mitigation / Workaround: N/A

Fix Text: CRD Schema validation is fixed to apply validation specific to the recordType setting.

1472745

Title: TMM container is restarted by Kubernetes

Component: fsm

Symptoms: The sock driver experiences tx_errors sending out packets on the veth interface (tmctl -d blade -w 250 tmm/xnet/sock/stats), as shown below:

ifname q_id mmap_ring_drops rx_buf_err rx_io_err   tx_err
------ ---- --------------- ---------- --------- --------
xeth0     0               0          0         0 70828320

Conditions: The TMM container’s veth mtu uses a value less than 1500.

Impact: Traffic disrupted while TMM restarts.

Mitigation / Workaround: None

Fix Text: To ensure TMM container doesn’t see any disruption in control plane and k3s traffic that receives on veth interface, TMM matches the mtu value between TMM container’s veth interface (eth0) and TMM’s internally created VLAN on top of the veth interface.

2241045

Title: ICMP monitor marks triggers pool member down alarm after 3 non-consecutive failures

Component: fsm

Symptoms: A pool member monitored by an ICMP health monitor may transition to DOWN even when probe failures are not consecutive.

In environments where intermittent packet loss occurs, the monitor may mark the endpoint as down after a single failed probe, even if successful probes occur between them.

The default monitor down threshold = 3, the following probe sequence triggers a DOWN state in the following scenario: FAIL → OK → FAIL → OK → FAIL

Instead of requiring three consecutive failures.

Conditions: With the default value of monitor down threshold = 3, this issue may occur when:

  • An ICMP health monitor is configured for a pool member.

  • Probe failures occur intermittently (e.g., due to packet filtering, network instability, or packet loss).

  • The system counts failed probes cumulatively rather than resetting the counter after successful probes.

Impact: Pool members may be marked DOWN prematurely even when the endpoint is still reachable, leading to incorrect pool member health state reporting.

Mitigation / Workaround: None

Fix Text: If the endpoint responds successfully shortly after being marked DOWN, this may indicate that the state change was triggered by intermittent probe failures rather than a persistent service outage. In particular, if the DOWN and subsequent UP events occur at intervals that match the configured monitor probe interval, this behavior may indicate that the endpoint is intermittently failing individual probes rather than experiencing a continuous outage.

Known issues

(No known issues)