On QFX10000 Series devices using Juniper Networks Junos OS when configured as transit IP/MPLS penultimate hop popping (PHP) nodes with link aggregation group (LAG) interfaces, an Improper Validation of Specified Index, Position, or Offset in Input weakness allows an attacker sending certain IP packets to cause multiple interfaces in the LAG to detach causing a Denial of Service (DoS) condition. Continued receipt and processing of these packets will sustain the Denial of Service.This issue affects IPv4 and IPv6 packets. Packets of either type can cause and sustain the DoS event.These packets can be destined to the device or be transit packets.On devices such as the QFX10008 with line cards, line cards can be restarted to restore service. On devices such as the QFX10002 you can restart the PFE service, or reboot device to restore service.This issue affects:Juniper Networks Junos OS on QFX10000 Series:
An indicator of compromise may be seen by issuing the command: request pfe execute target fpc0 command "show jspec pechip[3] registers ps l2_node 10" timeout 0 | refresh 1 | no-moreand reviewing for backpressured output; for example: GOT: 0x220702a8 pe.ps.l2_node[10].pkt_cnt 00000076 GOT: 0x220702b4 pe.ps.l2_node[10].backpressured 00000002 <<<< STICKS HEREand requesting detail on the pepic wanio: request pfe execute target fpc0 command "show pepic 0 wanio-info" timeout 0 | no-more | match xe-0/0/0:2GOT: 3 xe-0/0/0:2 10 6 3 0 1 10 189 10 0x6321b088 <<< LOOK HEREas well as looking for tail drops looking at the interface queue, for example: show interfaces queue xe-0/0/0:2resulting in: Transmitted: Total-dropped packets: 1094137 0 pps << LOOK HEREThe following minimal configuration is required to be potentially impacted by this issue:
[interfaces <interface> unit <unit> family inet address <address/mask>][interfaces <interface> unit <unit> family mpls][protocols rsvp interface <interface>][protocols mpls interface <interface>][protocols ospf area <area> interface <interface>]Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2022-22223.
The following software releases have been updated to resolve this specific issue: 15.1R7-S11, 18.4R2-S10, 18.4R3-S10, 19.1R3-S8, 19.2R3-S4, 19.3R3-S5, 19.4R2-S6, 19.4R3-S7, 20.1R3-S3, 20.2R3-S3, 20.3R3-S2, 20.4R3-S4, 21.1R3, 21.2R3-S3, 21.3R3-S1 21.4R1, and all subsequent releases.
This issue is being tracked as PR 1618728 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://support.juniper.net/support/downloads/.
Customers can apply the following PFE VTY commands as a workaround until a fixed release can be taken:bringup jspec write pechip[0] register egp main init_params 36 00000068bringup jspec write pechip[1] register egp main init_params 36 00000068bringup jspec write pechip[2] register egp main init_params 36 00000068bringup jspec write pechip[3] register egp main init_params 36 00000068bringup jspec write pechip[4] register egp main init_params 36 00000068bringup jspec write pechip[5] register egp main init_params 36 00000068This workaround must be reapplied upon any reboot.