SB2023011181 - Memory leak in Juniper Junos OS



SB2023011181 - Memory leak in Juniper Junos OS

Published: January 11, 2023

Security Bulletin ID SB2023011181
Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Memory leak (CVE-ID: CVE-2023-22414)

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

A Missing Release of Memory after Effective Lifetime vulnerability in Flexible PIC Concentrator (FPC) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker from the same shared physical or logical network, to cause a heap memory leak and leading to FPC crash.

 On all Junos PTX Series and QFX10000 Series, when specific EVPN VXLAN Multicast packets are processed, an FPC memory leak is observed.


Remediation

Install update from vendor's website.