An Improper Input Validation vulnerability in the Packet Forwarding Engine of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to cause memory leak, leading to Denial of Service (DoS).
On all Junos OS QFX5000 Series platforms, when pseudo-VTEP (Virtual Tunnel End Point) is configured under EVPN-VXLAN scenario, and specific DHCP packets are transmitted, DMA memory leak is observed. Continuous receipt of these specific DHCP packets will cause memory leak to reach 99% and then cause the protocols to stop working and traffic is impacted, leading to Denial of Service (DoS) condition. A manual reboot of the system recovers from the memory leak.
To confirm the memory leak, monitor for sheaf:possible leak and vtep not found messages in the logs.
This issue affects:
Juniper Networks Junos OS QFX5000 Series:
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Junos | Juniper | * | 20.4 (excluding) |
Junos | Juniper | 20.4 (including) | 20.4 (including) |
Junos | Juniper | 20.4-r1 (including) | 20.4-r1 (including) |
Junos | Juniper | 20.4-r1-s1 (including) | 20.4-r1-s1 (including) |
Junos | Juniper | 20.4-r2 (including) | 20.4-r2 (including) |
Junos | Juniper | 20.4-r2-s1 (including) | 20.4-r2-s1 (including) |
Junos | Juniper | 20.4-r2-s2 (including) | 20.4-r2-s2 (including) |
Junos | Juniper | 20.4-r3 (including) | 20.4-r3 (including) |
Junos | Juniper | 20.4-r3-s1 (including) | 20.4-r3-s1 (including) |
Junos | Juniper | 20.4-r3-s2 (including) | 20.4-r3-s2 (including) |
Junos | Juniper | 20.4-r3-s3 (including) | 20.4-r3-s3 (including) |
Junos | Juniper | 20.4-r3-s4 (including) | 20.4-r3-s4 (including) |
Junos | Juniper | 20.4-r3-s5 (including) | 20.4-r3-s5 (including) |
Junos | Juniper | 21.1 (including) | 21.1 (including) |
Junos | Juniper | 21.1-r1 (including) | 21.1-r1 (including) |
Junos | Juniper | 21.1-r1-s1 (including) | 21.1-r1-s1 (including) |
Junos | Juniper | 21.1-r2 (including) | 21.1-r2 (including) |
Junos | Juniper | 21.1-r2-s1 (including) | 21.1-r2-s1 (including) |
Junos | Juniper | 21.1-r2-s2 (including) | 21.1-r2-s2 (including) |
Junos | Juniper | 21.1-r3 (including) | 21.1-r3 (including) |
Junos | Juniper | 21.1-r3-s1 (including) | 21.1-r3-s1 (including) |
Junos | Juniper | 21.1-r3-s2 (including) | 21.1-r3-s2 (including) |
Junos | Juniper | 21.1-r3-s3 (including) | 21.1-r3-s3 (including) |
Junos | Juniper | 21.1-r3-s4 (including) | 21.1-r3-s4 (including) |
Junos | Juniper | 21.2 (including) | 21.2 (including) |
Junos | Juniper | 21.2-r1 (including) | 21.2-r1 (including) |
Junos | Juniper | 21.2-r1-s1 (including) | 21.2-r1-s1 (including) |
Junos | Juniper | 21.2-r1-s2 (including) | 21.2-r1-s2 (including) |
Junos | Juniper | 21.2-r2 (including) | 21.2-r2 (including) |
Junos | Juniper | 21.2-r2-s1 (including) | 21.2-r2-s1 (including) |
Junos | Juniper | 21.2-r2-s2 (including) | 21.2-r2-s2 (including) |
Junos | Juniper | 21.2-r3 (including) | 21.2-r3 (including) |
Junos | Juniper | 21.2-r3-s1 (including) | 21.2-r3-s1 (including) |
Junos | Juniper | 21.2-r3-s2 (including) | 21.2-r3-s2 (including) |
Junos | Juniper | 21.2-r3-s3 (including) | 21.2-r3-s3 (including) |
Junos | Juniper | 21.2-r3-s4 (including) | 21.2-r3-s4 (including) |
Junos | Juniper | 21.3 (including) | 21.3 (including) |
Junos | Juniper | 21.3-r1 (including) | 21.3-r1 (including) |
Junos | Juniper | 21.3-r1-s1 (including) | 21.3-r1-s1 (including) |
Junos | Juniper | 21.3-r1-s2 (including) | 21.3-r1-s2 (including) |
Junos | Juniper | 21.3-r2 (including) | 21.3-r2 (including) |
Junos | Juniper | 21.3-r2-s1 (including) | 21.3-r2-s1 (including) |
Junos | Juniper | 21.3-r2-s2 (including) | 21.3-r2-s2 (including) |
Junos | Juniper | 21.3-r3 (including) | 21.3-r3 (including) |
Junos | Juniper | 21.3-r3-s1 (including) | 21.3-r3-s1 (including) |
Junos | Juniper | 21.3-r3-s2 (including) | 21.3-r3-s2 (including) |
Junos | Juniper | 21.3-r3-s3 (including) | 21.3-r3-s3 (including) |
Junos | Juniper | 21.4 (including) | 21.4 (including) |
Junos | Juniper | 21.4-r1 (including) | 21.4-r1 (including) |
Junos | Juniper | 21.4-r1-s1 (including) | 21.4-r1-s1 (including) |
Junos | Juniper | 21.4-r1-s2 (including) | 21.4-r1-s2 (including) |
Junos | Juniper | 21.4-r2 (including) | 21.4-r2 (including) |
Junos | Juniper | 21.4-r2-s1 (including) | 21.4-r2-s1 (including) |
Junos | Juniper | 21.4-r2-s2 (including) | 21.4-r2-s2 (including) |
Junos | Juniper | 21.4-r3 (including) | 21.4-r3 (including) |
Junos | Juniper | 21.4-r3-s1 (including) | 21.4-r3-s1 (including) |
Junos | Juniper | 21.4-r3-s2 (including) | 21.4-r3-s2 (including) |
Junos | Juniper | 22.1-r1 (including) | 22.1-r1 (including) |
Junos | Juniper | 22.1-r1-s1 (including) | 22.1-r1-s1 (including) |
Junos | Juniper | 22.1-r1-s2 (including) | 22.1-r1-s2 (including) |
Junos | Juniper | 22.1-r2 (including) | 22.1-r2 (including) |
Junos | Juniper | 22.1-r2-s1 (including) | 22.1-r2-s1 (including) |
Junos | Juniper | 22.1-r2-s2 (including) | 22.1-r2-s2 (including) |
Junos | Juniper | 22.1-r3 (including) | 22.1-r3 (including) |
Junos | Juniper | 22.1-r3-s1 (including) | 22.1-r3-s1 (including) |
Junos | Juniper | 22.2 (including) | 22.2 (including) |
Junos | Juniper | 22.2-r1 (including) | 22.2-r1 (including) |
Junos | Juniper | 22.2-r1-s1 (including) | 22.2-r1-s1 (including) |
Junos | Juniper | 22.2-r1-s2 (including) | 22.2-r1-s2 (including) |
Junos | Juniper | 22.2-r2 (including) | 22.2-r2 (including) |
Junos | Juniper | 22.2-r2-s1 (including) | 22.2-r2-s1 (including) |
Junos | Juniper | 22.3-r1 (including) | 22.3-r1 (including) |
Junos | Juniper | 22.3-r1-s1 (including) | 22.3-r1-s1 (including) |
Junos | Juniper | 22.3-r1-s2 (including) | 22.3-r1-s2 (including) |
Junos | Juniper | 22.3-r2 (including) | 22.3-r2 (including) |
Junos | Juniper | 22.3-r2-s1 (including) | 22.3-r2-s1 (including) |
Junos | Juniper | 22.4-r1 (including) | 22.4-r1 (including) |
Junos | Juniper | 22.4-r1-s1 (including) | 22.4-r1-s1 (including) |