Multiple vulnerabilities in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allow an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific packets over VXLAN which cause either a memory leak which will ultimately result in an FPC reset or directly an FPC reset.
One or more of these issues affect:
Juniper Networks Junos OS
These issues do not affect versions of Junos OS prior to 19.4R1.
For these issues to be exploitable a configuration like the following will have to exist:
[ routing-instances <RI-name> instance-type virtual-switch ]
[ routing-instances <RI-name> bridge-domains <BD-name> vlan-id <vlan#n> ]
[ routing-instances <RI-name> bridge-domains <BD-name> vxlan ... ]
[ interfaces ae0 unit <unit#> vlan-id <vlan#n> ]
[ interfaces ae0 unit <unit#> family inet(6) address ... ]
Juniper SIRT is not aware of any malicious exploitation of these vulnerabilities.
These issues were seen during production usage.
The following issues have been reported:
The following software Junos OS releases have been updated to resolve these specific issues: 19.4R3-S7, 20.1R3-S3, 20.2R3-S3, 20.3R3-S2, 20.4R3-S1, 21.1R3, 21.2R2, 21.3R1-S1, 21.3R2, 21.4R1, and all subsequent releases.
These issues are being tracked as 1602407 and 1625292 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
2022-01-12: Initial Publication.