SB2023011184 - Use after free in Junos OS Evolved
Published: January 11, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Use after free (CVE-ID: CVE-2023-22402)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to use after free error in the kernel. A remote non-authenticated attacker can cause a Denial of Service (DoS).
In a Non Stop Routing (NSR) scenario, an unexpected kernel restart might be observed if "bgp auto-discovery" is enabled and if there is a BGP neighbor flap of auto-discovery sessions for any reason.
This is a race condition which is outside of an attackers direct control and it depends on system internal timing whether this issue occurs.
Remediation
Install update from vendor's website.