An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a Denial of Service (DoS).
When an incoming RESV message corresponding to a protected LSP is malformed it causes an incorrect internal state resulting in an rpd core.
This issue affects:
Juniper Networks Junos OS
To be affected by this issue the device must be configured with node protection for at least one LSP with either of:
[protocols rsvp mpls label-switched-path <lsp-name> node-protection]
[protocols rsvp mpls label-switched-path <lsp-name> node-link-protection]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was found during internal product security testing or research.
This issue has been assigned CVE-2022-22238.
The following software releases have been updated to resolve this specific issue:
Junos OS: 19.4R3-S8, 20.1R3-S2, 20.2R3-S3, 20.3R3-S2, 20.4R3-S1, 21.1R3, 21.2R1-S2, 21.2R3, 21.3R2, 21.4R1, and all subsequent releases.
Junos OS Evolved: 20.2R3-S3-EVO, 20.4R3-S1-EVO, 21.3R2-EVO, 21.4R1-EVO, and all subsequent releases.
This issue is being tracked as PR 1560059 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
Software Releases, patches and updates are available at https://support.juniper.net/support/downloads/.