CVE detail

CVE-2020-1679 — CVE-2020-1679

Published 2020-10-16 · Modified 2026-06-17 · Vendor juniper · Product junos · Source nvd
HIGH
severity
CVSS-derived band
7.5
CVSS v3
0–10 scale
0.0124
EPSS probability
exploitation probability, 30d
66.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog

Description

On Juniper Networks PTX and QFX Series devices with packet sampling configured using tunnel-observation mpls-over-udp, sampling of a malformed packet can cause the Kernel Routing Table (KRT) queue to become stuck. KRT is the module within the Routing Process Daemon (RPD) that synchronized the routing tables with the forwarding tables in the kernel. This table is then synchronized to the Packet Forwarding Engine (PFE) via the KRT queue. Thus, when KRT queue become stuck, it can lead to unexpected packet forwarding issues. An administrator can monitor the following command to check if there is the KRT queue is stuck: user@device > show krt state ... Number of async queue entries: 65007 <--- this value keep on increasing. When this issue occurs, the following message might appear in the /var/

Remediation

vendor remediation guidance

The following software releases have been updated to resolve this specific issue: Junos OS 17.2X75-D105, 18.1R3-S11, 18.2R3-S5, 18.2X75-D420, 18.2X75-D53, 18.2X75-D65, 18.3R2-S4, 18.3R3-S3, 18.4R1-S7, 18.4R2-S5, 18.4R3-S4, 19.1R2-S2, 19.1R3-S2, 19.2R1-S5, 19.2R3, 19.3R2-S3, 19.3R3, 19.4R1-S2, 19.4R2-S1, 19.4R3, 20.1R1-S2, 20.1R2, 20.2R1, 20.3X75-D10, and all subsequent releases.

workarounds

Disable sampling on all the interfaces will prevent the issue from occurring. If the device is experiencing the issue, the administrator can perform the follow steps to restore KRT queue: 1. Disable sampling configuration on this FPC user@device> deactivate chassis fpc<slot-no> sampling-instance <instance-name> 2. Restart multi-svcs process on this FPC by killing the process. The multi-svcs will get stared automatically once it gets killed and resume normal processing.

ProductVulnerable rangeFixed versionAdvisory
Juniper Networks Junos OS>=17.2X75<17.2X75-D10517.2X75-D105advisory ↗
Juniper Networks Junos OS>=18.1<18.1R3-S1118.1R3-S11advisory ↗
Juniper Networks Junos OS>=18.2<18.2R3-S518.2R3-S5advisory ↗
Juniper Networks Junos OS>=18.2X75<18.2X75-D420, 18.2X75-D53, 18.2X75-D6518.2X75-D420, 18.2X75-D53, 18.2X75-D65advisory ↗
Juniper Networks Junos OS>=18.3<18.3R2-S4, 18.3R3-S318.3R2-S4, 18.3R3-S3advisory ↗
Juniper Networks Junos OS>=18.4<18.4R1-S7, 18.4R2-S5, 18.4R3-S418.4R1-S7, 18.4R2-S5, 18.4R3-S4advisory ↗
Juniper Networks Junos OS>=19.1<19.1R2-S2, 19.1R3-S219.1R2-S2, 19.1R3-S2advisory ↗
Juniper Networks Junos OS>=19.2<19.2R1-S5, 19.2R319.2R1-S5, 19.2R3advisory ↗
Juniper Networks Junos OS>=19.3<19.3R2-S3, 19.3R319.3R2-S3, 19.3R3advisory ↗
Juniper Networks Junos OS>=19.4<19.4R1-S2, 19.4R2-S1, 19.4R319.4R1-S2, 19.4R2-S1, 19.4R3advisory ↗
Juniper Networks Junos OS>=20.1<20.1R1-S2, 20.1R220.1R1-S2, 20.1R2advisory ↗

References

cvedb.io · NVD · CISA KEV · FIRST EPSS · vendor advisories (CVE Program List v5). Informational only, no warranty — verify every remediation against the vendor advisory before acting on it. This product uses data from the NVD API but is not endorsed or certified by the NVD, CISA, FIRST.org or any vendor named. CVE® is a registered trademark of The MITRE Corporation.