A vulnerability in the processing of inbound IPv6 packets in Juniper Networks Junos OS on QFX5000 Series and EX4600 switches may cause the memory to not be freed, leading to a packet DMA memory leak, and eventual Denial of Service (DoS) condition. Once the condition occurs, further packet processing will be impacted, creating a sustained Denial of Service (DoS) condition.
The following error logs may be observed using the " show heap " command and the device may eventually run out of memory if such packets are received continuously.
show heap
Jan 12 12:00:00 device-name fpc0 (buf alloc) failed allocating packet buffer
Jan 12 12:00:01 device-name fpc0 (buf alloc) failed allocating packet buffer
user@device-name> request pfe execute target fpc0 timeout 30 command "show heap"
ID Base Total(b) Free(b) Used(b) % Name
-- ---------- ----------- ----------- ----------- --- -----------
0 246fc1a8 536870488 353653752 183216736 34 Kernel
1 91800000 16777216 12069680 4707536 28 DMA
2 92800000 75497472 69997640 5499832 7 PKT DMA DESC
3 106fc000 335544320 221425960 114118360 34 Bcm_sdk
4 97000000 176160768 200 176160568 99 Packet DMA
5 903fffe0 20971504 20971504 0 0 Blob
This issue affects Juniper Networks Junos OS on QFX5000 Series, EX4600:
This issue does not affect Juniper Networks Junos OS:
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2022-22174 .
The following software releases have been updated to resolve this specific issue: Junos OS 18.3R3-S6, 18.4R2-S9, 18.4R3-S9, 19.1R2-S3, 19.1R3-S7, 19.2R1-S8, 19.2R3-S3, 19.3R2-S7, 19.3R3-S4, 19.4R2-S5, 19.4R3-S6, 20.1R3-S1, 20.2R3-S2, 20.3R3-S1, 20.4R3, 21.1R2-S1, 21.1R3, 21.2R1-S1, 21.2R2, 21.3R1, 21.4R1, and all subsequent releases.
This issue is being tracked as 1603531 .
Software releases or updates are available for download at https://support.juniper.net/support/downloads/
2022-01-12: Initial Publication.