An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Throttling vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated network attacker to cause latency in transit packet processing and even packet loss.
If transit traffic includes a significant percentage (> 5%) of fragmented packets which need to be reassembled, high latency or packet drops might be observed.
This issue affects Juniper Networks Junos OS on SPC3 used in SRX5000 series and MX series, SRX4000 series, and vSRX :
This is issue does not affect SRX300 series, SRX550, SRX1500 and cSRX. Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2022-22153 .
The following software releases have been updated to resolve this specific issue: 18.2R3, 18.3R3, 18.4R2-S9, 18.4R3, 19.1R2, 19.2R1-S1, 19.2R2, 19.3R1, and all subsequent releases.
This issue is being tracked as 1406465 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
2022-01-12: Initial Publication. 2022-02-18: Affected platforms updated.