An improper input validation vulnerability in the Routing Protocol Daemon (RPD) service of Juniper Networks Junos OS allows an attacker to send a malformed RSVP packet when bidirectional LSPs are in use, which when received by an egress router crashes the RPD causing a Denial of Service (DoS) condition. Continued receipt of the packet will sustain the Denial of Service. This issue affects: Juniper Networks Junos OS: All versions prior to 17.3R3-S10 except 15.1X49-D240 for SRX series; 17.4 versions prior to 17.4R3-S2; 18.1 versions prior to 18.1R3-S10; 18.2 versions prior to 18.2R2-S7, 18.2R3-S4; 18.3 versions prior to 18.3R3-S2; 18.4 versions prior to 18.4R1-S8, 18.4R2-S6, 18.4R3-S2; 19.1 versions prior to 19.1R1-S5, 19.1R3-S3; 19.2 versions prior to 19.2R3; 19.3 versions prior to 19.3R2-S
The following software releases have been updated to resolve this specific issue: Junos OS: 15.1X49-D240, 17.3R3-S10, 17.4R3-S2, 18.1R3-S10, 18.2R2-S7, 18.2R3-S4, 18.3R3-S2, 18.4R1-S8, 18.4R2-S6, 18.4R3-S2, 19.1R1-S5, 19.1R3-S3, 19.2R3, 19.3R2-S5, 19.3R3, 19.4R2-S2, 19.4R3-S1, 20.1R1-S4, 20.1R2, 20.2R1, and all subsequent releases. Note: With the exception of SRX Series products using version 15.1X49-D240, all products using Junos OS prior to 17.3R3-S10 are affected and will not be fixed by Juniper Networks, Inc. Junos OS Evolved: 19.3R2-S5-EVO, 19.4R2-S2-EVO, 20.1R1-S4-EVO, and all subsequent releases.
If bidirectional LSPs are running in the network, when changing family mpls maximum-labels on an interface, first disable RSVP for this interface. You can include the disable statement at the following hierarchy levels: [edit protocols rsvp interface interface-name ] [edit logical-systems logical-system-name protocols rsvp interface interface-name ] See the MPLS RSVP disable configuration guide for further details.
| Product | Vulnerable range | Fixed version | Advisory |
|---|---|---|---|
| Juniper Networks Junos OS | >=15.1X49<15.1X49-D240 | 15.1X49-D240 | advisory ↗ |
| Juniper Networks Junos OS | >=unspecified<17.3R3-S10 | 17.3R3-S10 | advisory ↗ |
| Juniper Networks Junos OS | >=17.4<17.4R3-S2 | 17.4R3-S2 | advisory ↗ |
| Juniper Networks Junos OS | >=18.1<18.1R3-S10 | 18.1R3-S10 | advisory ↗ |
| Juniper Networks Junos OS | >=18.2<18.2R2-S7, 18.2R3-S4 | 18.2R2-S7, 18.2R3-S4 | advisory ↗ |
| Juniper Networks Junos OS | >=18.3<18.3R3-S2 | 18.3R3-S2 | advisory ↗ |
| Juniper Networks Junos OS | >=18.4<18.4R1-S8, 18.4R2-S6, 18.4R3-S2 | 18.4R1-S8, 18.4R2-S6, 18.4R3-S2 | advisory ↗ |
| Juniper Networks Junos OS | >=19.1<19.1R1-S5, 19.1R3-S3 | 19.1R1-S5, 19.1R3-S3 | advisory ↗ |
| Juniper Networks Junos OS | >=19.2<19.2R3 | 19.2R3 | advisory ↗ |
| Juniper Networks Junos OS | >=19.3<19.3R2-S5, 19.3R3 | 19.3R2-S5, 19.3R3 | advisory ↗ |
| Juniper Networks Junos OS | >=19.4<19.4R2-S2, 19.4R3-S1 | 19.4R2-S2, 19.4R3-S1 | advisory ↗ |
| Juniper Networks Junos OS | >=20.1<20.1R1-S4, 20.1R2 | 20.1R1-S4, 20.1R2 | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=19.3<19.3R2-S5-EVO | 19.3R2-S5-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=19.4<19.4R2-S2-EVO | 19.4R2-S2-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=20.1<20.1R1-S4-EVO | 20.1R1-S4-EVO | advisory ↗ |