SB2021041504 - Memory leak when querying Aggregated Ethernet (AE) interface statistics in Junos OS
Published: April 15, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2021-0230)
The vulnerability allows a local user to perform DoS attack on the target system.
The vulnerability exists due memory leak On Juniper Networks Junos OS platforms with link aggregation (lag) configured. A local user can execute any operation that fetches Aggregated Ethernet (AE) interface statistics, including but not limited to SNMP GET requests, and trigger a slow kernel memory leak.
Remediation
Install update from vendor's website.