6.5
CVSSv3

CVE-2023-22406

Published: 13/01/2023 Updated: 24/01/2023
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A Missing Release of Memory after Effective Lifetime vulnerability in the kernel of Juniper Networks Junos OS and Junos OS Evolved allows an adjacent, unauthenticated malicious user to cause a Denial of Service (DoS). In a segment-routing scenario with OSPF as IGP, when a peer interface continuously flaps, next-hop churn will happen and a continuous increase in Routing Protocol Daemon (rpd) memory consumption will be observed. This will eventually lead to an rpd crash and restart when the memory is full. The memory consumption can be monitored using the CLI command "show task memory detail" as shown in the following example: user@host> show task memory detail | match "RT_NEXTHOPS_TEMPLATE|RT_TEMPLATE_BOOK_KEE" RT_NEXTHOPS_TEMPLATE 1008 1024 T 50 51200 50 51200 RT_NEXTHOPS_TEMPLATE 688 768 T 50 38400 50 38400 RT_NEXTHOPS_TEMPLATE 368 384 T 412330 158334720 412330 158334720 RT_TEMPLATE_BOOK_KEE 2064 2560 T 33315 85286400 33315 85286400 user@host> show task memory detail | match "RT_NEXTHOPS_TEMPLATE|RT_TEMPLATE_BOOK_KEE" RT_NEXTHOPS_TEMPLATE 1008 1024 T 50 51200 50 51200 RT_NEXTHOPS_TEMPLATE 688 768 T 50 38400 50 38400 RT_NEXTHOPS_TEMPLATE 368 384 T 419005 160897920 419005 160897920 <=== RT_TEMPLATE_BOOK_KEE 2064 2560 T 39975 102336000 39975 10233600 <=== This issue affects: Juniper Networks Junos OS All versions before 19.3R3-S7; 19.4 versions before 19.4R2-S8, 19.4R3-S9; 20.2 versions before 20.2R3-S5; 20.3 versions before 20.3R3-S5; 20.4 versions before 20.4R3-S4; 21.1 versions before 21.1R3-S3; 21.2 versions before 21.2R3-S2; 21.3 versions before 21.3R3-S1; 21.4 versions before 21.4R2-S1, 21.4R3; 22.1 versions before 22.1R2. Juniper Networks Junos OS Evolved All versions before 20.4R3-S4-EVO; 21.4 versions before 21.4R2-S1-EVO, 21.4R3-EVO; 22.1 versions before 22.1R2-EVO.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

juniper junos 19.3

juniper junos 19.4

juniper junos 20.2

juniper junos 20.3

juniper junos 20.4

juniper junos 21.1

juniper junos 21.2

juniper junos 21.3

juniper junos 21.4

juniper junos 22.1

juniper junos

juniper junos os evolved 20.4

juniper junos os evolved

juniper junos os evolved 21.4

juniper junos os evolved 22.1