An Out-of-Bounds Write vulnerability in Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause Denial of Service (DoS).
On SRX Series devices using Unified Policies with IPv6, when a specific IPv6 packet goes through a dynamic-application filter which will generate an ICMP deny message, the flowd core is observed and the PFE is restarted.
This issue affects:
Juniper Networks Junos OS on SRX Series:
Security policy with dynamic-application Junos:QUIC (or similar applications) need to be configured for this issue to be present.
[set security zones security-zone trust]
[set security zones security-zone untrust]
[set security policies from-zone trust to-zone untrust policy p3 match source-address any]
[set security policies from-zone trust to-zone untrust policy p3 match destination-address any]
[set security policies from-zone trust to-zone untrust policy p3 match dynamic-application junos:QUIC]
[set security policies from-zone trust to-zone untrust policy p3 then permit]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
This issue has been assigned CVE-2023-22411.
The following software releases have been updated to resolve this specific issue: 19.2R3-S6, 19.3R3-S6, 19.4R3-S9, 20.2R3-S5, 20.3R3-S4, 20.4R3-S3, 21.1R3, 21.2R3, 21.3R2, 21.4R2, 22.1R1, and all subsequent releases.
This issue is being tracked as 1601806.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2023-01-11: Initial Publication