On Juniper Networks Junos OS devices configured as a DHCP forwarder, the Juniper Networks Dynamic Host Configuration Protocol Daemon (jdhcp) process might crash when receiving a malformed DHCP packet.
This issue only affects devices configured as DHCP forwarder with forward-only option, that forward specified DHCP client packets, without creating a new subscriber session.
The jdhcpd daemon automatically restarts without intervention, but continuous receipt of the malformed DHCP packet will repeatedly crash jdhcpd, leading to an extended Denial of Service (DoS) condition.
This issue can be triggered only by DHCPv4, it cannot be triggered by DHCPv6.
This issue affects Juniper Networks Junos OS:
The examples of the config stanza affected by this issue:
[forwarding-options dhcp-relay forward-only]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2020-1661 .
The following software releases have been updated to resolve this specific issue: Junos OS 12.3R12-S16, 12.3X48-D105, 15.1R7-S7, 15.1X49-D221, 15.1X49-D230, 15.1X53-D593, 16.1R7-S5, 16.2R1 and all subsequent releases.
This issue is being tracked as 1430874 .
Software releases or updates are available for download at https://www.juniper.net/support/downloads/ .
There are no viable workarounds for this issue.
2020-10-14: Initial Publication.