SB2022011705 - Denial of service when handling fragmented packets in Junos OS
Published: January 17, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Inefficient algorithmic complexity (CVE-ID: CVE-2022-22153)
The vulnerability allows a remote attacker to perform DoS attack.
The vulnerability exists due to insufficient algorithmic complexity along with an error of resource allocation in the flow processing daemon (flowd) on SRX Series and MX Series with SPC3. A remote attacker can cause latency in transit packet processing and even packet loss, if transit traffic includes a significant percentage (> 5%) of fragmented packets.
Remediation
Install update from vendor's website.