A Missing Release of Memory after Effective Lifetime vulnerability in the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS).
In a scenario where Public Key Infrastructure (PKI) is used in combination with Certificate Revocation List (CRL), if the CRL fails to download the memory allocated to store the CRL is not released. Repeated occurrences will eventually consume all available memory and lead to an inoperable state of the affected system causing a DoS.
This issue affects Juniper Networks Junos OS:
This issue can be observed by monitoring the memory utilization of the pkid process via:
root@jtac-srx1500-r2003> show system processes extensive | match pki
20931 root 20 0 733M 14352K select 0:00 0.00% pkid
which increases over time:
22587 root 20 0 901M 181M select 0:03 0.00% pkid
To be affected a system would need to be configured with:
[ security pki ca-profile <ca-profile-name> revocation-check crl url <url-name> ]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2022-22173 .
The following software releases have been updated to resolve this specific issue: 18.3R3-S6, 18.4R2-S9, 18.4R3-S10, 19.1R2-S3, 19.1R3-S7, 19.2R1-S8, 19.2R3-S4, 19.3R3-S4, 19.4R2-S5, 19.4R3-S5, 20.1R3-S1, 20.2R3-S2, 20.3R3-S1, 20.4R3, 21.1R2, 21.1R3, 21.2R1-S1, 21.2R2, 21.3R1, and all subsequent releases.
This issue is being tracked as 1602815 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
2022-01-12: Initial Publication.