An Improper Handling of Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a network-based, unauthenticated attacker to send a specific routing update, causing an rpd core due to memory corruption, leading to a Denial of Service (DoS). This issue can only be triggered when the system is configured for CoS-based forwarding (CBF) with a policy map containing a cos-next-hop-map action (see below). This issue affects: Junos OS: * all versions before 20.4R3-S10, * from 21.2 before 21.2R3-S8, * from 21.3 before 21.3R3, * from 21.4 before 21.4R3, * from 22.1 before 22.1R2; Junos OS Evolved: * all versions before 21.2R3-S8-EVO, * from 21.3 before 21.3R3-EVO, * from 21.4 before 21.
The following software releases have been updated to resolve this specific issue: Junos OS: 20.4R3-S10, 21.3R3, 21.4R3, 22.1R2, 22.2R1, and all subsequent releases. Junos OS Evolved: 21.3R3-EVO, 21.4R3-EVO, 22.1R2-EVO, 22.2R1-EVO, and all subsequent releases.
There are no known workarounds for this issue.
| Product | Vulnerable range | Fixed version | Advisory |
|---|---|---|---|
| Juniper Networks Junos OS | <20.4R3-S10 | 20.4R3-S10 | advisory ↗ |
| Juniper Networks Junos OS | >=21.2<21.2R3-S8 | 21.2R3-S8 | advisory ↗ |
| Juniper Networks Junos OS | >=21.3<21.3R3 | 21.3R3 | advisory ↗ |
| Juniper Networks Junos OS | >=21.4<21.4R3 | 21.4R3 | advisory ↗ |
| Juniper Networks Junos OS | >=22.1<22.1R2 | 22.1R2 | advisory ↗ |
| Juniper Networks Junos OS Evolved | <21.2R3-S8-EVO | 21.2R3-S8-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=21.3<21.3R3-EVO | 21.3R3-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=21.4<21.4R3-EVO | 21.4R3-EVO | advisory ↗ |
| Juniper Networks Junos OS Evolved | >=22.1<22.1R2-EVO | 22.1R2-EVO | advisory ↗ |