A Heap-based Buffer Overflow vulnerability in the Network Services Daemon (NSD) of Juniper Networks Junos OS allows authenticated, low privileged, local attacker to cause a Denial of Service (DoS).
On an SRX 5000 Series device, when executing a specific command repeatedly, memory is corrupted, which leads to a Flow Processing Daemon (flowd) crash.
The NSD process has to be restarted to restore services.
If this issue occurs, it can be checked with the following command:
user@host> request security policies check The following log message can also be observed:
Error: policies are out of sync for PFE node.fpc.pic. This issue affects:
Juniper Networks Junos OS on SRX 5000 Series
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Name | Vendor | Start Version | End Version |
---|---|---|---|
Junos | Juniper | * | 20.4 (excluding) |
Junos | Juniper | 20.4 (including) | 20.4 (including) |
Junos | Juniper | 20.4-r1 (including) | 20.4-r1 (including) |
Junos | Juniper | 20.4-r1-s1 (including) | 20.4-r1-s1 (including) |
Junos | Juniper | 20.4-r2 (including) | 20.4-r2 (including) |
Junos | Juniper | 20.4-r2-s1 (including) | 20.4-r2-s1 (including) |
Junos | Juniper | 20.4-r2-s2 (including) | 20.4-r2-s2 (including) |
Junos | Juniper | 20.4-r3 (including) | 20.4-r3 (including) |
Junos | Juniper | 20.4-r3-s1 (including) | 20.4-r3-s1 (including) |
Junos | Juniper | 20.4-r3-s2 (including) | 20.4-r3-s2 (including) |
Junos | Juniper | 20.4-r3-s3 (including) | 20.4-r3-s3 (including) |
Junos | Juniper | 20.4-r3-s4 (including) | 20.4-r3-s4 (including) |
Junos | Juniper | 20.4-r3-s5 (including) | 20.4-r3-s5 (including) |
Junos | Juniper | 21.1 (including) | 21.1 (including) |
Junos | Juniper | 21.1-r1 (including) | 21.1-r1 (including) |
Junos | Juniper | 21.1-r1-s1 (including) | 21.1-r1-s1 (including) |
Junos | Juniper | 21.1-r2 (including) | 21.1-r2 (including) |
Junos | Juniper | 21.1-r2-s1 (including) | 21.1-r2-s1 (including) |
Junos | Juniper | 21.1-r2-s2 (including) | 21.1-r2-s2 (including) |
Junos | Juniper | 21.1-r3 (including) | 21.1-r3 (including) |
Junos | Juniper | 21.1-r3-s1 (including) | 21.1-r3-s1 (including) |
Junos | Juniper | 21.1-r3-s2 (including) | 21.1-r3-s2 (including) |
Junos | Juniper | 21.1-r3-s3 (including) | 21.1-r3-s3 (including) |
Junos | Juniper | 21.1-r3-s4 (including) | 21.1-r3-s4 (including) |
Junos | Juniper | 21.2 (including) | 21.2 (including) |
Junos | Juniper | 21.2-r1 (including) | 21.2-r1 (including) |
Junos | Juniper | 21.2-r1-s1 (including) | 21.2-r1-s1 (including) |
Junos | Juniper | 21.2-r1-s2 (including) | 21.2-r1-s2 (including) |
Junos | Juniper | 21.2-r2 (including) | 21.2-r2 (including) |
Junos | Juniper | 21.2-r2-s1 (including) | 21.2-r2-s1 (including) |
Junos | Juniper | 21.2-r2-s2 (including) | 21.2-r2-s2 (including) |
Junos | Juniper | 21.2-r3 (including) | 21.2-r3 (including) |
Junos | Juniper | 21.2-r3-s1 (including) | 21.2-r3-s1 (including) |
Junos | Juniper | 21.2-r3-s2 (including) | 21.2-r3-s2 (including) |
Junos | Juniper | 21.2-r3-s3 (including) | 21.2-r3-s3 (including) |
Junos | Juniper | 21.3 (including) | 21.3 (including) |
Junos | Juniper | 21.3-r1 (including) | 21.3-r1 (including) |
Junos | Juniper | 21.3-r1-s1 (including) | 21.3-r1-s1 (including) |
Junos | Juniper | 21.3-r1-s2 (including) | 21.3-r1-s2 (including) |
Junos | Juniper | 21.3-r2 (including) | 21.3-r2 (including) |
Junos | Juniper | 21.3-r2-s1 (including) | 21.3-r2-s1 (including) |
Junos | Juniper | 21.3-r2-s2 (including) | 21.3-r2-s2 (including) |
Junos | Juniper | 21.3-r3 (including) | 21.3-r3 (including) |
Junos | Juniper | 21.3-r3-s1 (including) | 21.3-r3-s1 (including) |
Junos | Juniper | 21.3-r3-s2 (including) | 21.3-r3-s2 (including) |
Junos | Juniper | 21.4 (including) | 21.4 (including) |
Junos | Juniper | 21.4-r1 (including) | 21.4-r1 (including) |
Junos | Juniper | 21.4-r1-s1 (including) | 21.4-r1-s1 (including) |
Junos | Juniper | 21.4-r1-s2 (including) | 21.4-r1-s2 (including) |
Junos | Juniper | 21.4-r2 (including) | 21.4-r2 (including) |
Junos | Juniper | 21.4-r2-s1 (including) | 21.4-r2-s1 (including) |
Junos | Juniper | 21.4-r2-s2 (including) | 21.4-r2-s2 (including) |
Junos | Juniper | 21.4-r3 (including) | 21.4-r3 (including) |
Junos | Juniper | 21.4-r3-s1 (including) | 21.4-r3-s1 (including) |
Junos | Juniper | 21.4-r3-s2 (including) | 21.4-r3-s2 (including) |
Junos | Juniper | 22.1 (including) | 22.1 (including) |
Junos | Juniper | 22.1-r1 (including) | 22.1-r1 (including) |
Junos | Juniper | 22.1-r1-s1 (including) | 22.1-r1-s1 (including) |
Junos | Juniper | 22.1-r1-s2 (including) | 22.1-r1-s2 (including) |
Junos | Juniper | 22.1-r2 (including) | 22.1-r2 (including) |
Junos | Juniper | 22.1-r2-s1 (including) | 22.1-r2-s1 (including) |
Junos | Juniper | 22.1-r2-s2 (including) | 22.1-r2-s2 (including) |
Junos | Juniper | 22.1-r3 (including) | 22.1-r3 (including) |
Junos | Juniper | 22.2 (including) | 22.2 (including) |
Junos | Juniper | 22.2-r1 (including) | 22.2-r1 (including) |
Junos | Juniper | 22.2-r1-s1 (including) | 22.2-r1-s1 (including) |
Junos | Juniper | 22.2-r1-s2 (including) | 22.2-r1-s2 (including) |
Junos | Juniper | 22.2-r2 (including) | 22.2-r2 (including) |
Junos | Juniper | 22.2-r2-s1 (including) | 22.2-r2-s1 (including) |
Junos | Juniper | 22.2-r2-s2 (including) | 22.2-r2-s2 (including) |
Junos | Juniper | 22.3 (including) | 22.3 (including) |
Junos | Juniper | 22.3-r1 (including) | 22.3-r1 (including) |
Junos | Juniper | 22.3-r1-s1 (including) | 22.3-r1-s1 (including) |
Junos | Juniper | 22.3-r1-s2 (including) | 22.3-r1-s2 (including) |