Junos OS: MX Series: An FPC crash might be seen due to mac-moves within the same bridge domain
Published Oct 18, 2022
6.5
MEDIUMCVSS 3.1
EPSS 0.46%
Description
An Improper Control of a Resource Through its Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on MX Series allows an unauthenticated adjacent attacker to cause a Denial of Service (DoS). When there is a continuous mac move a memory corruption causes one or more FPCs to crash and reboot. These MAC moves can be between two local interfaces or between core/EVPN and local interface. The below error logs can be seen in PFE syslog when this issue happens: xss_event_handler(1071): EA[0:0]_PPE 46.xss[0] ADDR Error. ppe_error_interrupt(4298): EA[0:0]_PPE 46 Errors sync xtxn error xss_event_handler(1071): EA[0:0]_PPE 1.xss[0] ADDR Error. ppe_error_interrupt(4298): EA[0:0]_PPE 1 Errors sync xtxn error xss_event_handler(1071): EA[0:0]_PPE 2.xss[0] ADDR Error. This issue affects Juniper Networks Junos OS on MX Series: All versions prior to 15.1R7-S13; 19.1 versions prior to 19.1R3-S9; 19.2 versions prior to 19.2R3-S6; 19.3 versions prior to 19.3R3-S6; 19.4 versions prior to 19.4R2-S7, 19.4R3-S8; 20.1 version 20.1R1 and later versions; 20.2 versions prior to 20.2R3-S5; 20.3 versions prior to 20.3R3-S5; 20.4 versions prior to 20.4R3-S2; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R3; 21.3 versions prior to 21.3R2.
Affected products
-
- Version 19.1StatusaffectedConstraints<19.1R3-S9
- Version 19.2StatusaffectedConstraints<19.2R3-S6
- Version 19.3StatusaffectedConstraints<19.3R3-S6
- Version 19.4StatusaffectedConstraints<19.4R2-S7, 19.4R3-S8
- Version 20.1R1StatusaffectedConstraints<20.1*
- Version 20.2StatusaffectedConstraints<20.2R3-S5
- Version 20.3StatusaffectedConstraints<20.3R3-S5
- Version 20.4StatusaffectedConstraints<20.4R3-S2
- Version 21.1StatusaffectedConstraints<21.1R3
- Version 21.2StatusaffectedConstraints<21.2R3
- Version 21.3StatusaffectedConstraints<21.3R2
- Version unspecifiedStatusaffectedConstraints<15.1R7-S13
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Juniper Networks | Junos OS | n/a |
|
- < 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 15.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.1
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.2
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.3
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 19.4
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.1
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.2
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.3
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 20.4
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.1
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.2
- 21.3
- 21.3
- 21.3
- 21.3
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
The following software releases have been updated to resolve this specific issue: 15.1R7-S13, 19.1R3-S9, 19.2R3-S6, 19.3R3-S6, 19.4R2-S7, 19.4R3-S8, 20.2R3-S5, 20.3R3-S5, 20.4R3-S2, 21.1R3, 21.2R3, 21.3R2, 21.4R1, and all subsequent releases.
References (1)
- https://kb.juniper.net/JSA69906 ExploitVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://kb.juniper.net/JSA69906 | ExploitVendor Advisory |
Change history (0)
No recorded changes yet.