A Missing Release of Memory after Effective Lifetime vulnerability in the Flow Processing Daemon (flowd) of Juniper Networks Junos OS allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS).
In an IPsec VPN environment, a memory leak will be seen if a DH or ECDH group is configured. Eventually the flowd process will crash and restart.
This issue affects Juniper Networks Junos OS on vSRX Series:
To be affected the system needs to run iked (vs. kmd which is not affected), which can be verified with:
show system processes extensive | match "KMD|IKED"Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
show system processes extensive | match "KMD|IKED"
This issue was seen during production usage.
This issue has been assigned CVE-2023-22417.
The following software releases have been updated to resolve this specific issue: 19.3R3-S7, 19.4R2-S8, 19.4R3-S10, 20.2R3-S6, 20.3R3-S5, 20.4R3-S5, 21.1R3-S4, 21.2R3, 21.3R3, 21.4R2, 22.1R1, and all subsequent releases.
This issue is being tracked as 1639998.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2023-01-11: Initial Publication 2023-01-25: Update the JSA to state that no all SRX Series device are affected but only vSRX Series running iked