Cloud-Native Network Functions on Robin.io 2.2.2 release notes¶
About this release¶
Introduction¶
These release notes describe the differences between CNFs on Robin.io 2.2.1 and 2.2.2.
Supported container-orchestration platforms¶
This release is officially supported on these container-orchestration platforms and versions:
| Platform | Version | Recommended Helm version |
|---|---|---|
| Robin.io | 5.4.3-616 | 3 or later |
| Robin.io | 5.4.3-564 | 3 or later |
| Robin.io | 5.4.3-302 | 3 or later |
| Robin.io | 5.3.11-217 | 3 or later |
Security updates¶
This section lists the F5 vulnerability bugs of this release.
| CVE Number | Bug IDs | Image Names | Package Name |
|---|---|---|---|
| CVE-2016-2781 | 2160477 | BaseOS | coreutils |
| CVE-2022-3219 | 2160481, 2226573 | BaseOS | gpgv |
| CVE-2025-0167 | 2159613, 2159849, 2159873, 2160293, 2226457, 2226653 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img | curl, libcurl4t64 |
| CVE-2025-10148 | 2159617, 2159853, 2159877, 2160297, 2226657 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img | curl, libcurl4t64 |
| CVE-2025-14017 | 2227153, 2231521, 2231525, 2231533 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress | curl, libcurl4t64 |
| CVE-2025-14524 | 2226461, 2226505, 2226601, 2226661, 2226709 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img | curl, libcurl4t64 |
| CVE-2025-14819 | 2226465, 2226509, 2226605, 2226665, 2226713 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img | curl, libcurl4t64 |
| CVE-2025-14831 | 2226737 | baseos | libgnutls30t64 |
| CVE-2025-15079 | 2226469, 2226513, 2226609, 2226669, 2226717 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img | curl, libcurl4t64 |
| CVE-2025-15224 | 2226473, 2226517, 2226613, 2226673, 2226721 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img | curl, libcurl4t64 |
| CVE-2025-5278 | 2251717 | baseos | coreutils |
| CVE-2025-6141 | 2251721 | baseos | libncursesw6 |
| CVE-2025-61984 | 2226549 | gslb-engine | openssh-client |
| CVE-2025-61985 | 2226553 | gslb-engine | openssh-client |
| CVE-2025-68121 | 2225665, 2226213, 2226233 | f5-dssm-upgrader, vault, vault-init | stdlib |
| CVE-2025-68972 | 2226569, 2226741 | baseos, rabbit | dirmngr, gpgv |
| CVE-2025-70873 | 2266997 | postgresql | sqlite-libs |
| CVE-2025-8277 | 2226477, 2226725 | f5-debug-sidecar, f5-fluentbit | libssh-4 |
| CVE-2025-8941 | 2160473 | baseos | libpam-modules |
| CVE-2025-9086 | 2159621, 2159857, 2159881, 2179697, 2226681 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img | curl, libcurl4t64 |
| CVE-2025-9820 | 2231537 | baseos | libgnutls30t64 |
| CVE-2026-0964 | 2226441, 2226697 | f5-debug-sidecar, f5-fluentbit | libssh-4 |
| CVE-2026-0965 | 2226481, 2226729 | f5-debug-sidecar, f5-fluentbit | libssh-4 |
| CVE-2026-0966 | 2226485, 2226733 | f5-debug-sidecar, f5-fluentbit | libssh-4 |
| CVE-2026-0967 | 2226445, 2226701 | f5-debug-sidecar, f5-fluentbit | libssh-4 |
| CVE-2026-0968 | 2226449, 2226705 | f5-debug-sidecar, f5-fluentbit | libssh-4 |
| CVE-2026-0994 | 2231529 | f5-l4p-engine | libprotobuf32t64 |
| CVE-2026-1229 | 2231185, 2231237 | vault, vault-init | github.com/cloudflare/circl |
| CVE-2026-1519 | 2267513 | f5-debug-sidecar | bind9-dnsutils |
| CVE-2026-1965 | 2242005, 2242021, 2242037, 2242053, 2242077, 2260557 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img, postgresql | curl, libcurl4t64 |
| CVE-2026-2003 | 2227165 | f5-fluentbit | libpq5 |
| CVE-2026-2004 | 2227169 | f5-fluentbit | libpq5 |
| CVE-2026-2005 | 2227173 | f5-fluentbit | libpq5 |
| CVE-2026-2006 | 2227177 | f5-fluentbit | libpq5 |
| CVE-2026-22184 | 2231173, 2231225 | vault, vault-init | zlib |
| CVE-2026-24051 | 2230977, 2231005, 2231177, 2231229 | cert-manager-controller, cert-manager-webhook, vault, vault-init | go.opentelemetry.io/otel/sdk |
| CVE-2026-24515 | 2226533, 2226557 | dnsx-img, spk-csrc | libexpat1 |
| CVE-2026-25210 | 2226537, 2226561 | dnsx-img, spk-csrc | libexpat1 |
| CVE-2026-25679 | 2230893, 2230905, 2230909, 2230913, 2230917, 2230921, 2230965, 2230981, 2230993, 2231009, 2231021, 2231033, 2231045, 2231057, 2231069, 2231081, 2231101, 2231113, 2231125, 2231137, 2231149, 2231161, 2231189, 2231201, 2231213, 2231241, 2231253, 2231265, 2231277, 2231289, 2231301, 2231313, 2231325, 2231337, 2231349, 2231361, 2231373, 2231385, 2231397, 2231409, 2231421, 2231433, 2231445, 2231457, 2231469, 2231481, 2231493, 2231505, 2231541, 2241981, 2241985, 2260445, 2266097, 2266949 | baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init | stdlib |
| CVE-2026-2673 | 2251709, 2266817 | baseos, vault-init | libcrypto3, libssl3t64 |
| CVE-2026-26958 | 2225733, 2226301, 2226437 | opentelemetry-collector-contri, vault, vault-init | filippo.io/edwards25519 |
| CVE-2026-27137 | 2231085, 2231749 | f5-csm-qkview, opentelemetry-collector-contri | stdlib |
| CVE-2026-27138 | 2231089, 2231753 | f5-csm-qkview, opentelemetry-collector-contri | stdlib |
| CVE-2026-27139 | 2230897, 2230925, 2230929, 2230933, 2230937, 2230941, 2230969, 2230985, 2230997, 2231013, 2231025, 2231037, 2231049, 2231061, 2231073, 2231093, 2231105, 2231117, 2231129, 2231141, 2231153, 2231165, 2231193, 2231205, 2231217, 2231245, 2231257, 2231269, 2231281, 2231293, 2231305, 2231317, 2231329, 2231341, 2231353, 2231365, 2231377, 2231389, 2231401, 2231413, 2231425, 2231437, 2231449, 2231461, 2231473, 2231485, 2231497, 2231509, 2231545, 2241997, 2242001, 2260453, 2266209, 2266981 | baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init | stdlib |
| CVE-2026-27142 | 2230901, 2230945, 2230949, 2230953, 2230957, 2230961, 2230973, 2230989, 2231001, 2231017, 2231029, 2231041, 2231053, 2231065, 2231077, 2231097, 2231109, 2231121, 2231133, 2231145, 2231157, 2231169, 2231197, 2231209, 2231221, 2231249, 2231261, 2231273, 2231285, 2231297, 2231309, 2231321, 2231333, 2231345, 2231357, 2231369, 2231381, 2231393, 2231405, 2231417, 2231429, 2231441, 2231453, 2231465, 2231477, 2231489, 2231501, 2231513, 2231549, 2241989, 2241993, 2260449, 2266145, 2266965 | baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init | stdlib |
| CVE-2026-27171 | 2231181, 2231233, 2251725 | baseos, vault, vault-init | zlib, zlib1g |
| CVE-2026-2781 | 2266989 | postgresql | nss-libs |
| CVE-2026-27820 | 2231517 | f5-fluentd | zlib |
| CVE-2026-28387 | 2266821, 2267001, 2267577 | baseos, postgresql, vault-init | libcrypto3, libssl3t64, openssl |
| CVE-2026-28388 | 2266785, 2267005, 2267581 | baseos, postgresql, vault-init | libcrypto3, libssl3t64, openssl |
| CVE-2026-28389 | 2266789, 2267009, 2267585 | baseos, postgresql, vault-init | libcrypto3, libssl3t64, openssl |
| CVE-2026-28390 | 2266765, 2267013, 2267589 | baseos, postgresql, vault-init | libcrypto3, libssl3t64, openssl |
| CVE-2026-29111 | 2267545, 2267557 | baseos, f5-fluentd | libsystemd-shared, libsystemd0 |
| CVE-2026-31789 | 2266825, 2267017, 2267593 | baseos, postgresql, vault-init | libcrypto3, libssl3t64, openssl |
| CVE-2026-31790 | 2266793, 2267021, 2267561 | baseos, postgresql, vault-init | libcrypto3, libssl3t64, openssl |
| CVE-2026-32280 | 2266069, 2266101, 2266105, 2266109, 2266113, 2266117, 2266233, 2266257, 2266289, 2266321, 2266349, 2266373, 2266397, 2266421, 2266445, 2266493, 2266517, 2266545, 2266569, 2266593, 2266617, 2266645, 2266717, 2266741, 2266769, 2266841, 2266865, 2266893, 2266921, 2266953, 2267029, 2267057, 2267081, 2267105, 2267133, 2267157, 2267185, 2267209, 2267233, 2267257, 2267281, 2267309, 2267333, 2267357, 2267381, 2267405, 2267429, 2267457, 2267485, 2267549 | baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init | stdlib |
| CVE-2026-32281 | 2266081, 2266149, 2266153, 2266157, 2266161, 2266165, 2266241, 2266273, 2266301, 2266333, 2266357, 2266381, 2266405, 2266429, 2266461, 2266501, 2266525, 2266553, 2266577, 2266601, 2266625, 2266673, 2266725, 2266749, 2266797, 2266849, 2266877, 2266905, 2266929, 2266969, 2267041, 2267065, 2267089, 2267117, 2267141, 2267169, 2267193, 2267217, 2267241, 2267265, 2267293, 2267317, 2267341, 2267365, 2267389, 2267413, 2267441, 2267465, 2267493, 2267565 | baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init | stdlib |
| CVE-2026-32282 | 2266073, 2266121, 2266125, 2266129, 2266133, 2266137, 2266237, 2266261, 2266293, 2266325, 2266353, 2266377, 2266401, 2266425, 2266449, 2266497, 2266521, 2266549, 2266573, 2266597, 2266621, 2266649, 2266721, 2266745, 2266773, 2266845, 2266869, 2266897, 2266925, 2266961, 2267033, 2267061, 2267085, 2267109, 2267137, 2267161, 2267189, 2267213, 2267237, 2267261, 2267285, 2267313, 2267337, 2267361, 2267385, 2267409, 2267433, 2267461, 2267489, 2267553 | baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init | stdlib |
| CVE-2026-32283 | 2266093, 2266213, 2266217, 2266221, 2266225, 2266229, 2266253, 2266285, 2266317, 2266345, 2266369, 2266393, 2266417, 2266441, 2266485, 2266513, 2266541, 2266565, 2266589, 2266613, 2266637, 2266705, 2266737, 2266761, 2266829, 2266861, 2266889, 2266917, 2266941, 2266985, 2267053, 2267077, 2267101, 2267129, 2267153, 2267181, 2267205, 2267229, 2267253, 2267277, 2267305, 2267329, 2267353, 2267377, 2267401, 2267425, 2267453, 2267481, 2267509, 2267597 | baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init | stdlib |
| CVE-2026-32285 | 2260485 | opentelemetry-collector-contri | github.com/buger/jsonparser |
| CVE-2026-32286 | 2260517, 2260537, 2260593 | f5-license-proxy, vault, vault-init | github.com/jackc/pgproto3/v2 |
| CVE-2026-32287 | 2260489 | opentelemetry-collector-contri | github.com/antchfx/xpath |
| CVE-2026-32288 | 2266085, 2266169, 2266173, 2266177, 2266181, 2266185, 2266245, 2266277, 2266305, 2266337, 2266361, 2266385, 2266409, 2266433, 2266465, 2266505, 2266529, 2266557, 2266581, 2266605, 2266629, 2266677, 2266729, 2266753, 2266801, 2266853, 2266881, 2266909, 2266933, 2266973, 2267045, 2267069, 2267093, 2267121, 2267145, 2267173, 2267197, 2267221, 2267245, 2267269, 2267297, 2267321, 2267345, 2267369, 2267393, 2267417, 2267445, 2267469, 2267497, 2267569 | baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init | stdlib |
| CVE-2026-32289 | 2266089, 2266189, 2266193, 2266197, 2266201, 2266205, 2266249, 2266281, 2266309, 2266341, 2266365, 2266389, 2266413, 2266437, 2266469, 2266509, 2266533, 2266561, 2266585, 2266609, 2266633, 2266681, 2266733, 2266757, 2266805, 2266857, 2266885, 2266913, 2266937, 2266977, 2267049, 2267073, 2267097, 2267125, 2267149, 2267177, 2267201, 2267225, 2267249, 2267273, 2267301, 2267325, 2267349, 2267373, 2267397, 2267421, 2267449, 2267473, 2267501, 2267573 | baseos, cert-manager-cainjector, cert-manager-controller, cert-manager-startupapicheck, cert-manager-webhook, crd-conversion, crd-installer, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-cert-client, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dssm-store, f5-dssm-upgrader, f5-dwbld, f5-env-discovery, f5-eowyn-install, f5-fluentbit, f5-fluentd, f5-fqdn-resolver, f5-ipam-controller, f5-l4p-engine, f5-license-helper, f5-license-proxy, f5-lifecycle-operator, f5-node-labeler, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, init-certmgr, ocnos-img, opentelemetry-collector-contri, rabbit, spk-csrc, spk-cwc, tmrouted-img, vault, vault-init | stdlib |
| CVE-2026-33186 | 2260425, 2260429, 2260433, 2260437, 2260441, 2260457, 2260461, 2260465, 2260469, 2260473, 2260481, 2260501, 2260505, 2260509, 2260513, 2260529, 2260533, 2260549, 2260569, 2260573, 2260577, 2260581, 2260585, 2260589, 2260597, 2260601, 2260605, 2260609, 2260613, 2266945 | cert-manager-controller, cert-manager-webhook, crdupdater, f5-analyzer, f5-bdosd, f5-blobd, f5-coremond, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-dwbld, f5-fluentd, f5-fqdn-resolver, f5-l4p-engine, f5-nsec-ips-daemon, f5-toda-observer, f5-toda-tmstatsd, f5-urlcat, f5dr-img, f5ing-tmm-pod-manager, f5ingress, ocnos-img, opentelemetry-collector-contri, spk-csrc, spk-cwc, vault, vault-init | google.golang.org/grpc |
| CVE-2026-33210 | 2260617 | f5-fluentd | json |
| CVE-2026-33810 | 2266489 | opentelemetry-collector-contri | stdlib |
| CVE-2026-33997 | 2260497, 2260525, 2260545 | opentelemetry-collector-contri, vault, vault-init | github.com/docker/docker |
| CVE-2026-34040 | 2260493, 2260521, 2260541 | opentelemetry-collector-contri, vault, vault-init | github.com/docker/docker |
| CVE-2026-3497 | 2242073 | gslb-engine | openssh-client |
| CVE-2026-34986 | 2266077, 2266141, 2266265, 2266297, 2266453, 2266653, 2266777, 2266873, 2266901, 2267037, 2267113, 2267165, 2267289, 2267437 | cert-manager-controller, crd-conversion, f5-csm-qkview, f5-debug-sidecar, f5-downloader, f5-license-helper, f5-license-proxy, f5-toda-observer, f5ing-tmm-pod-manager, f5ingress, opentelemetry-collector-contri, spk-cwc, vault, vault-init | github.com/go-jose/go-jose/v3, github.com/go-jose/go-jose/v4 |
| CVE-2026-35206 | 2267477 | f5-lifecycle-operator | helm.sh/helm/v3 |
| CVE-2026-3731 | 2242009, 2242025, 2242041, 2242057, 2242081 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img | libssh-4 |
| CVE-2026-3783 | 2242013, 2242029, 2242045, 2242061, 2242085, 2260561 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img, postgresql | curl, libcurl4t64 |
| CVE-2026-3784 | 2242017, 2242033, 2242049, 2242065, 2242089, 2260565 | crd-installer, f5-debug-sidecar, f5-fluentbit, f5ingress, ocnos-img, postgresql | curl, libcurl4t64 |
| CVE-2026-3805 | 2260553 | postgresql | curl |
| CVE-2026-39882 | 2266473 | opentelemetry-collector-contri | go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp |
| CVE-2026-39883 | 2266269, 2266329, 2266457, 2266657, 2266781 | cert-manager-controller, cert-manager-webhook, opentelemetry-collector-contri, vault, vault-init | go.opentelemetry.io/otel/sdk |
| CVE-2026-40179 | 2266313, 2266537, 2267505 | f5-coremond, f5-csm-qkview, f5-fluentd | github.com/prometheus/prometheus |
| CVE-2026-40200 | 2266833 | vault-init | musl |
| CVE-2026-4105 | 2251713 | baseos | libsystemd0 |
| CVE-2026-4437 | 2267025 | postgresql | glibc |
| CVE-2026-4438 | 2266993 | postgresql | glibc |
| CVE-2026-4878 | 2266685, 2266809 | vault, vault-init | libcap |
| CVE-2026-6042 | 2266837 | vault-init | musl |
New features¶
(No new features)
Enhancements¶
(No new enhancements)
Model changes¶
(No model changes)
Fixed issues¶
2263137-1¶
Title: Path-slice extraction on long URIs may cause TMM exit
Component: fsm-hudfilters
Symptoms: TMM can crash when a request’s URI path exceeds the xbuf MSS and a rule compares a path slice (a subsection of the URI path).
Conditions: When an administrator configures an iRule, ServiceBasedInterface static route, or TDR filter to compare a URI path “slice” (subsection) and the path exceeds the MSS, issues can occur. A slice is specified with the Path pseudo-header (:p) plus the slash-delimited segment range; for example, :p:s3-5 selects the 3rd–5th path segments.
Impact: Incorrect code branch causes TMM termination.
Mitigation / Workaround: N/A
Fix Text: Path-slice comparisons behave correctly for any URI path length.
2221753-1¶
Title: F5BigCneDatagroup configuration fails for non-address data types
Component: CRD
Symptoms: Datagroup configuration with “recordType: string” or “recordType: integer” fails with schema validation errors such as the following, preventing valid configurations.
: Invalid value: “”: “spec.records[0].key” must validate one and only one schema (oneOf). Found none valid.
Conditions: The Datagroup data type is specified via the “recordType” setting, which can be set to “address,” “integer,” or “string”. However for all datatypes, the CRD schema validation wrongly enforces IP Address validation, preventing “string” & “integer” data type configs to always fail.
Impact: Datagroup supports only the IP Address recordType and does not support the “integer” & “string” types.
Mitigation / Workaround: N/A
Fix Text: CRD Schema validation is fixed to apply validation specific to the recordType setting.
1472745¶
Title: TMM container is restarted by Kubernetes
Component: fsm
Symptoms: The sock driver experiences tx_errors sending out packets on the veth interface (tmctl -d blade -w 250 tmm/xnet/sock/stats), as shown below:
ifname q_id mmap_ring_drops rx_buf_err rx_io_err tx_err
------ ---- --------------- ---------- --------- --------
xeth0 0 0 0 0 70828320
Conditions: The TMM container’s veth mtu uses a value less than 1500.
Impact: Traffic disrupted while TMM restarts.
Mitigation / Workaround: None
Fix Text: To ensure TMM container doesn’t see any disruption in control plane and k3s traffic that receives on veth interface, TMM matches the mtu value between TMM container’s veth interface (eth0) and TMM’s internally created VLAN on top of the veth interface.
2241045¶
Title: ICMP monitor marks triggers pool member down alarm after 3 non-consecutive failures
Component: fsm
Symptoms: A pool member monitored by an ICMP health monitor may transition to DOWN even when probe failures are not consecutive.
In environments where intermittent packet loss occurs, the monitor may mark the endpoint as down after a single failed probe, even if successful probes occur between them.
The default monitor down threshold = 3, the following probe sequence triggers a DOWN state in the following scenario: FAIL → OK → FAIL → OK → FAIL
Instead of requiring three consecutive failures.
Conditions: With the default value of monitor down threshold = 3, this issue may occur when:
An ICMP health monitor is configured for a pool member.
Probe failures occur intermittently (e.g., due to packet filtering, network instability, or packet loss).
The system counts failed probes cumulatively rather than resetting the counter after successful probes.
Impact: Pool members may be marked DOWN prematurely even when the endpoint is still reachable, leading to incorrect pool member health state reporting.
Mitigation / Workaround: None
Fix Text: If the endpoint responds successfully shortly after being marked DOWN, this may indicate that the state change was triggered by intermittent probe failures rather than a persistent service outage. In particular, if the DOWN and subsequent UP events occur at intervals that match the configured monitor probe interval, this behavior may indicate that the endpoint is intermittently failing individual probes rather than experiencing a continuous outage.
Known issues¶
(No known issues)