Product Affected

This issue affects Junos OS 18.4, 19.1, 19.2, 19.4, 20.2, 20.3, 20.4, 21.1. This issue affects all versions of Junos OS Evolved.
Medium
5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H)

Problem

A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Routing Protocol Daemon (rpd) of Juniper Networks Junos OS, Junos OS Evolved allows a network-based unauthenticated attacker to cause a Denial of Service (DoS).

When a BGP flow route with redirect IP extended community is received, and the reachability to the next-hop of the corresponding redirect IP is flapping, the rpd process might crash. Whether the crash occurs depends on the timing of the internally processing of these two events and is outside the attackers control. Please note that this issue also affects Route-Reflectors unless 'routing-options flow firewall-install-disable' is configured.

This issue affects:

Juniper Networks Junos OS:

  • 18.4 versions prior to 18.4R2-S10, 18.4R3-S10;
  • 19.1 versions prior to 19.1R3-S7;
  • 19.2 versions prior to 19.2R1-S8, 19.2R3-S4;
  • 19.4 versions prior to 19.4R3-S8;
  • 20.2 versions prior to 20.2R3-S3;
  • 20.3 versions prior to 20.3R3-S2;
  • 20.4 versions prior to 20.4R3;
  • 21.1 versions prior to 21.1R2.

Juniper Networks Junos OS Evolved:

  • All versions prior to 20.4R2-EVO;
  • 21.1-EVO versions prior to 21.1R2-EVO.

This issue does not affect Juniper Networks Junos OS versions prior to 18.4R1.

To be vulnerable to this issue a device needs to be configured with a minimal BGP flow spec configuration like in the following example:

[protocols bgp group <group-name> family <family> flow]

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

This issue was seen during production usage.

This issue has been assigned CVE-2022-22220.

Solution

The following software releases have been updated to resolve this specific issue:

Junos OS: 18.4R2-S10, 18.4R3-S10, 19.1R3-S7, 19.2R1-S8, 19.2R3-S4, 19.4R3-S8, 20.2R3-S3, 20.3R3-S2, 20.4R3, 21.1R2, 21.2R1, and all subsequent releases.

Junos OS Evolved: 20.4R2-EVO, 21.1R2-EVO, 21.2R1-EVO, and all subsequent releases.

This issue is being tracked as PR 1583490 which is visible on the Customer Support website.

Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).

IMPLEMENTATION:

Software Releases, patches and updates are available at https://support.juniper.net/support/downloads/.

Workaround

There are no viable workarounds for this issue.

Severity Assessment

Information for how Juniper Networks uses CVSS can be found at KB 16446 [juniper.net] "Common Vulnerability Scoring System (CVSS) and Juniper's Security Advisories."

Modification History

2022-10-12: Initial Publication.

Related Information