SB2021041505 - Memory leak in VPLS in Juniper Junos OS



SB2021041505 - Memory leak in VPLS in Juniper Junos OS

Published: April 15, 2021

Security Bulletin ID SB2021041505
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Memory leak (CVE-ID: CVE-2021-0257)

The vulnerability allows a remote attacker to perform DoS attack on the target system.

The vulnerability exists due memory leak. On Juniper Networks MX Series and EX9200 Series platforms with Trio-based MPCs (Modular Port Concentrators) where Integrated Routing and Bridging (IRB) interfaces are configured and mapped to a VPLS instance or a Bridge-Domain, certain Layer 2 network events at Customer Edge (CE) devices may cause memory leaks in the MPC of Provider Edge (PE) devices which can cause an out of memory condition and MPC restart.


Remediation

Install update from vendor's website.