An Uncontrolled Resource Consumption vulnerability in the Layer 2 Address Learning Daemon (l2ald) of Juniper Networks Junos OS Evolved allows an unauthenticated, adjacent attacker to cause a memory leak, eventually exhausting all system memory, leading to a system crash and Denial of Service (DoS).Certain MAC table updates cause a small amount of memory to leak. Once memory utilization reaches its limit, the issue will result in a system crash and restart.To identify the issue, execute the CLI command:user@device> show platform application-info allocations app l2ald-agentEVL Object Allocation Statistics:Node Application Context Name Live Allocs Fails Guidsre0 l2ald-agent net::juniper::rtnh::L2Rtinfo 1069096 1069302 0 1069302re0 l2ald-agent net::juniper::rtnh::NHOpaqueTlv 114 195 0 195
This issue affects Junos OS Evolved:
Juniper SIRT is not aware of any malicious exploitation of this vulnerability.
This issue was seen during production usage.
The following software releases have been updated to resolve this specific issue: 21.4R3-S8-EVO, 22.2R3-S4-EVO, 22.3R3-S3-EVO, 22.4R3-EVO, 23.2R2-EVO, 23.4R1-EVO, and all subsequent releases.
This issue is being tracked as 1756208 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
2024-07-10: Initial Publication 2024-09-13: Minor formatting change to CVSS field