A security-related vulnerability was recently discovered in the JUNOS software. This vulnerability is described in detail in the FreeBSD Security Advisory FreeBSD-SA-02:09.fstatfs and in PR/21769. A user logged in to a Juniper Networks router could panic the JUNOS kernel by calling the fstatfs() system call using an invalid file descriptor. (The descriptor becomes invalid because the file is deleted.) Only file descriptors that refer to files in a procfs file system are known to exploit this race condition.
The fstatfs() system call was updated to remove the race condition.
The fix is included in all versions of JUNOS software released on or after February 10, 2002.