An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to memory corruption, leading to a Denial of Service (DoS).This issue can only be triggered when the system is configured for CoS-based forwarding (CBF) with a policy map containing a cos-next-hop-map action (see below).This issue affects:Junos OS:
Junos OS Evolved:
The following is an example of CoS-based forwarding configuration:[edit policy-options]set policy-statement my-cos-forwarding term 1 from route-filter destination-prefix match-typeset policy-statement my-cos-forwarding term 1 then cos-next-hop-map map-name
The following software releases have been updated to resolve this specific issue:
This issue is being tracked as 1640813 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2024-04-10 - Initial Publication 2024-09-13: Minor formatting change to CVSS field2024-12-03: Mentioned fixes for 21.2R3-S8 and 21.2R3-S8-EVO