In the releases affected, JUNOS IPSec implementation does not ensure that an IPSec packet is long enough to contain the required authentication data. As a result, spoofing very short ESP or AH packets with known source, destination, Security Payload Identifier, and a high sequence number can cause a kernel panic. This problem is documented as PR/27664.
The IPSec code was modified to correctly verify that IPSec packets are of sufficient length to include the required authentication data.
Customers should install an updated release of JUNOS software. All releases of JUNOS software built on or after August 23rd, 2002, contain the fix. As a work-around, customers can implement a firewall filter and apply it to the lo0 interface to prevent delivery of IPSec ESP and AH packets. Alternatively, customers can remove all IPSec configuration from the router to avoid the vulnerability.