SB2022071358 - Memory leak in Juniper Junos OS
Published: July 13, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Memory leak (CVE-ID: CVE-2022-22204)
The vulnerability allows a remote non-authenticated attacker to perform service disruption.
An Improper Release of Memory Before Removing Last Reference vulnerability in the Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Juniper Networks Junos OS allows unauthenticated network based attacker to cause a partial Denial of Service (DoS).
On all MX and SRX platforms, if the SIP ALG is enabled, receipt of a specific SIP packet will create a stale SIP entry.
Remediation
Install update from vendor's website.