When a specific BGP flowspec configuration is enabled and upon receipt of a specific matching BGP packet meeting a specific term in the flowspec configuration, a reachable assertion failure occurs, causing the routing protocol daemon (rpd) process to crash with a core file being generated.
Affected releases are Juniper Networks Junos OS:
The following maximal parent* configuration is required:
set protocols bgp group [FLOWSPEC]
and
set policy-options policy-statement
set routing-options flow term-order
Specific child* relationship configuration details vary by implementation which may introduce this vulnerability.
*"parent" and "child" as in a parent-child tree structure relationship within the CLI.
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2019-0003 .
The following software releases have been updated to resolve this specific issue: 12.1X46-D77, 12.3R12-S10, 12.3X48-D70, 14.1X53-D47, 15.1F3, 15.1R3, 15.1X49-D140, 15.1X53-D59, 16.1R1 and all subsequent releases.
This issue is being tracked as PR 1116761 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://www.juniper.net/support/downloads/ .
Disable BGP flowspec.
There are no other available workarounds for this issue.
2019-01-09: Initial Publication.