An Improper Check for Unusual or Exceptional Conditions vulnerability in the Layer 2 Address Learning Daemon (l2ald) on Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause Denial of Service (DoS).In an EVPN/VXLAN scenario, when a high amount specific Layer 2 packets are processed by the device, it can cause the Routing Protocol Daemon (rpd) to utilize all CPU resources which causes the device to hang. A manual restart of the rpd is required to restore services.This issue affects both IPv4 and IPv6 implementations.
This issue affectsJunos OS:All versions earlier than 21.4R3-S7;22.1 versions earlier than 22.1R3-S5;22.2 versions earlier than 22.2R3-S3;22.3 versions earlier than 22.3R3-S3;22.4 versions earlier than 22.4R3-S2;23.2 versions earlier than 23.2R2;23.4 versions earlier than 23.4R1-S1.
Junos OS Evolved:All versions earlier than 21.4R3-S7-EVO;22.1-EVO versions earlier than 22.1R3-S5-EVO;22.2-EVO versions earlier than 22.2R3-S3-EVO;22.3-EVO versions earlier than 22.3R3-S3-EVO;22.4-EVO versions earlier than 22.4R3-S2-EVO;23.2-EVO versions earlier than 23.2R2-EVO;23.4-EVO versions earlier than 23.4R1-S1-EVO, 23.4R2-EVO.Required configuration for exposure:
EVPN is configured on the device: [protocols evpn]
To be exposed to this issue the device needs be configured for VXLAN with either of the following statements:
[vlans <vlan> vxlan] [routing-instances <routing-instance> vxlan]
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was found during internal product security testing or research.
The following software releases have been updated to resolve this specific issue: Junos OS: 21.4R3-S7, 22.1R3-S5, 22.2R3-S3, 22.3R3-S3, 22.4R3-S2, 23.2R2, 23.4R1-S1, 23.4R2, 24.2R1, and all subsequent releases.Junos OS Evolved: 21.4R3-S7-EVO, 22.1R3-S5-EVO, 22.2R3-S3-EVO, 22.3R3-S3-EVO, 22.4R3-S2-EVO, 23.2R2-EVO, 23.4R1-S1-EVO, 23.4R2-EVO, 24.2R1-EVO, and all subsequent releases.
This issue is being tracked as 1783346 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
There are no known workarounds for this issue.
2024-07-10: Initial Publication 2024-09-13: Minor formatting change to CVSS field