Certain crafted BGP UPDATE messages are incorrectly determined to contain an Invalid Path Attribute. Upon receipt of one of these UPDATE message, a NOTIFY message is sent to the peer with an error code of "UPDATE message error" (3) and a sub-code of "Malformed Attribute List" (1), and the peering session is terminated. The peering session will usually be re-established; however, as soon as the peer re-sends the crafted UPDATE message the session will once again be torn down. The resulting "flapping" of the BGP session causes increased control traffic between the BGP peers, and requires CPU resources to process the routing information. Additionally, as the routing information received on the affected peering session changes, BGP route damping can occur elsewhere in the Internet, resulting in sub-optimal routing or traffic loss. Due to the nature of the BGP protocol, it is not necessary for these crafted BGP UPDATE messages to originate from the router's immediate neighbor. The crafted messages can be propagated from a remotely located source. These issues are tracked in PR/264283 and PR/261211. US/CERT has assigned VU#929656 to this vulnerability.
All JUNOS software releases built on or after December 8, 2007 have been corrected to properly handle these crafted BGP UPDATE messages.
Customers running the BGP protocol are strongly urged to update their routers to a version of JUNOS software that contains the corrected code. There is no work-around for this issue.