Junos OS: QFX5000 Series and MX Series: An l2alm crash leading to an FPC crash can be observed in VxLAN scenario
Published Jul 20, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.32%
Description
A NULL Pointer Dereference vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on QFX5000 Series and MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). On QFX5K Series and MX Series, when the PFE receives a specific VxLAN packet the Layer 2 Address Learning Manager (L2ALM) process will crash leading to an FPC reboot. Continued receipt of this specific packet will create a sustained Denial of Service (DoS) condition. This issue affects Juniper Networks Junos OS on QFX5000 Series, MX Series: 20.3 versions prior to 20.3R3-S3; 20.4 versions prior to 20.4R3-S2; 21.2 versions prior to 21.2R2-S1. This issue does not affect Juniper Networks Junos OS: All versions prior to 20.3R1; 21.1 version 21.1R1 and later versions.
Affected products
-
- Version 20.3StatusaffectedConstraints<20.3R3-S3
- Version 20.4StatusaffectedConstraints<20.4R3-S2
- Version 21.2StatusaffectedConstraints<21.2R2-S1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos OS | n/a |
|
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve this specific issue: 20.3R3-S3, 20.4R3-S2, 21.2R2-S1, and all subsequent releases.
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27357 Advisory
- https://kb.juniper.net/JSA69714 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-27357 | Advisory | |
| https://kb.juniper.net/JSA69714 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.