Description

When sFlow is enabled and it monitors a packet forwarded via ECMP, a buffer management vulnerability in the dcpfe process of Juniper Networks Junos OS on QFX10K Series systems allows an attacker to cause the Packet Forwarding Engine (PFE) to crash and restart by sending specific genuine packets to the device, resulting in a Denial of Service (DoS) condition. Please refer to https://kb.juniper.net/JSA70195 [juniper.net] for more information.

Symptoms

Packet Forwarding Engine might crash when SFLOW is enabled and the mirrored packet is forwarded via ECMP.

 

DCPFE core dumps will be seeing:

 

user@QFX10000> show system core-dumps no-forwarding

-rw-r--r-- 1 root wheel 37432805 Feb 1 14:55 /var/tmp/fpc-1.dcpfe.core.0.tgz

-rw-r--r-- 1 root wheel 22001120 Feb 1 15:25 /var/tmp/fpc-1.dcpfe.core.1.tgz

-rw-r--r-- 1 root wheel 22067468 Feb 1 16:26 /var/tmp/fpc-1.dcpfe.core.2.tgz

Solution

Temporarily disable sFlow or upgrading to the following releases.

junos:19.4R3-S9 junos:20.2R3-S6 junos:20.2R3-S7 junos:20.3R3-S6 junos:20.4R3-S5 junos:21.1R3-S4 junos:21.2R3-S3 junos:21.2X32-D10 junos:21.3R3-S2 junos:21.4R2-S2 junos:21.4R3 junos:22.1R2 junos:22.1R3 junos:22.2R1-S2 junos:22.2R2 junos:22.3R1 junos:22.4R1

Modification History

05/19 - Changing from WIP to non-validated