SB2022011705 - Denial of service when handling fragmented packets in Junos OS



SB2022011705 - Denial of service when handling fragmented packets in Junos OS

Published: January 17, 2022

Security Bulletin ID SB2022011705
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Inefficient algorithmic complexity (CVE-ID: CVE-2022-22153)

The vulnerability allows a remote attacker to perform DoS attack.

The vulnerability exists due to insufficient algorithmic complexity along with an error of resource allocation in the flow processing daemon (flowd) on SRX Series and MX Series with SPC3. A remote attacker can cause latency in transit packet processing and even packet loss, if transit traffic includes a significant percentage (> 5%) of fragmented packets.


Remediation

Install update from vendor's website.