CVSS: v3.1: 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)CVSS: v4.0: 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L)
An Out-of-Bounds Read vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated network-based attacker sending a specifically malformed BGP packet to cause rpd to crash and restart, resulting in a Denial of Service (DoS). Continued receipt and processing of this packet will create a sustained Denial of Service (DoS) condition.This issue only affects systems configured in either of two ways:
This issue can affect iBGP and eBGP with any address family configured. The specific attribute involved is non-transitive, and will not propagate across a network.
This issue affects:
Junos OS:
Junos OS Evolved:
One of the following traceoptions configurations, either at the top level, under [logical-systems], or [routing-instances], is required to be potentially exposed to this issue:[protocols bgp traceoptions packets detail][protocols bgp traceoptions update detail][protocols bgp group <group-name> traceoptions packets detail][protocols bgp group <group-name> traceoptions update detail][protocols bgp group <group-name> neighbor <address> traceoptions packets detail][protocols bgp group <group-name> neighbor <address> traceoptions update detail]Systems configured with BGP traffic engineering are also vulnerable to this issue:[protocols bgp group <name> family traffic-engineering unicast]
The following software releases have been updated to resolve this specific issue:Junos OS: 21.4R3-S8, 22.2R3-S5*, 22.3R3-S4*, 22.4R3-S3, 23.2R2-S2, 23.4R2, 24.2R1, and all subsequent releases.Junos OS Evolved: 21.4R3-S8-EVO, 22.2R3-S5-EVO*, 22.3R3-S4-EVO*, 22.4R3-S3-EVO, 23.2R2-S2-EVO, 23.4R2-EVO, 24.2R1-EVO, 24.2R2-EVO, 24.4R1-EVO*, and all subsequent releases.*Future release
This issue is being tracked as 1815222 which is visible on the Customer Support website.
Note: Juniper SIRT's policy is not to evaluate releases which are beyond End of Engineering (EOE) or End of Life (EOL).
If BGP traceoptions are enabled, and traffic engineering is not configured, disable BGP traceoptions if they are not being used for active troubleshooting.
2024-10-09: Initial Publication2024-10-09: Removed references to segment routing and added traceoptions requirement2024-10-16: Added additional detail that two specific scenarios are vulnerable to this issue
Juniper SIRT would like to acknowledge and thank Craig Dods from Meta’s Infrastructure Security Engineering team for responsibly reporting this vulnerability.