An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated malicious user to send a specific routing update, causing an rpd core due to memory corruption, leading to a Denial of Service (DoS). This issue can only be triggered when the system is configured for CoS-based forwarding (CBF) with a policy map containing a cos-next-hop-map action (see below). This issue affects: Junos OS: * all versions prior to 20.4R3-S10, * from 21.2 prior to 21.2R3-S8, * from 21.3 prior to 21.3R3, * from 21.4 prior to 21.4R3, * from 22.1 prior to 22.1R2; Junos OS Evolved: * all versions prior to 21.2R3-S8-EVO, * from 21.3 prior to 21.3R3-EVO, * from 21.4 prior to 21.4R3-EVO, * from 22.1 prior to 22.1R2-EVO.