A vulnerability in Juniper Networks Junos OS on SRX Series, allows a network-based unauthenticated attacker to cause a Denial of Service (DoS) by sending a specific fragmented packet to the device, resulting in a flowd process crash, which is responsible for packet forwarding.
Continued receipt and processing of this specific packet will create a sustained DoS condition.
This issue only affects SRX Series when 'preserve-incoming-fragment-size' feature is enabled.
This issue affects Juniper Networks Junos OS on SRX Series:
This issue does not affect Juniper Networks Junos OS prior to 17.3R1.
The config stanza affected by this issue:
[ security flow preserve-incoming-fragment-size ]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2022-22185.
The following software releases have been updated to resolve this specific issue: 18.3R3-S6, 18.4R3-S10, 19.1R3-S7, 19.2R3-S4, 19.3R3-S4, 19.4R3-S6, 20.1R3-S2, 20.2R3-S3, 20.3R3-S1, 20.4R3, 21.1R2-S1, 21.1R3, 21.2R2, 21.3R1, and all subsequent releases.
This issue is being tracked as PR 1607782 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://support.juniper.net/support/downloads/.
An administrator can disable the feature preserve-incoming-fragment-size to avoid this issue:
user@host# delete security flow preserve-incoming-fragment-size
user@host# commit
2022-04-13: Initial Publication.