In a Segment Routing ISIS (SR-ISIS)/MPLS environment, on Juniper Networks Junos OS and Junos OS Evolved devices, configured with ISIS Flexible Algorithm for Segment Routing and sensor-based statistics, a flap of a ISIS link in the network, can lead to a routing process daemon (RPD) crash and restart, causing a Denial of Service (DoS). Continued link flaps will create a sustained Denial of Service (DoS) condition. This issue affects: Juniper Networks Junos OS: 19.4 versions prior to 19.4R1-S4, 19.4R3-S2; 20.1 versions prior to 20.1R2-S1, 20.1R3; 20.2 versions prior to 20.2R2-S2, 20.2R3; 20.3 versions prior to 20.3R2; Juniper Networks Junos OS Evolved: 20.3-EVO versions prior to 20.3R2-EVO; 20.4-EVO versions prior to 20.4R2-EVO. This issue does not affect: Juniper Networks Junos OS releases
The following software releases have been updated to resolve this specific issue: Junos OS: 19.4R1-S4, 19.4R3-S2, 20.1R2-S1, 20.1R3, 20.2R2-S2, 20.2R3, 20.3R2, 20.4R1, and all subsequent releases. Junos OS Evolved: 20.3R2-EVO, 20.4R2-EVO, 21.1R1-EVO, and all subsequent releases.
Disabling IS-IS Flexible Algorithm for Segment Routing or sensor-based statistics will mitigate this issue.
| Product | Vulnerable range | Fixed version | Advisory |
|---|---|---|---|
| Juniper Networks Junos OS | >=19.4R1<19.4* | 19.4* | advisory ↗ |
| Juniper Networks Junos OS | >=20.1<20.1R2-S1, 20.1R3 | 20.1R2-S1, 20.1R3 | advisory ↗ |
| Juniper Networks Junos OS | >=20.2<20.2R2-S2, 20.2R3 | 20.2R2-S2, 20.2R3 | advisory ↗ |
| Juniper Networks Junos OS | >=20.3<20.3R2 | 20.3R2 | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=19.4R1-EVO<19.4* | 19.4* | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=20.1R1-EVO<20.1* | 20.1* | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=20.2R1-EVO<20.2* | 20.2* | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=20.3<20.3R2-EVO | 20.3R2-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=20.4<20.4R2-EVO | 20.4R2-EVO | advisory ↗ |