Time-of-check Time-of-use (TOCTOU) Race Condition in Junos OS and Junos OS Evolved - CVE-2022-22225
Published: October 12, 2022
Vulnerability identifier: #VU68272
CSH Severity: Medium
CVSS v4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22225
CWE-ID: CWE-367
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to preform a denial of service (DoS) attack.
The vulnerability exists due to a race condition in the Routing Protocol Daemon (rpd). In a BGP multipath scenario, when one of the contributing routes is flapping often and rapidly, rpd may crash.
Affected software
Junos OS
Junos OS Evolved
Junos OS Evolved
How to mitigate CVE-2022-22225
Install updates from vendor's website.
Junos OS - addressed in versions 19.2R3-S6, 20.2R3-S4, 20.3R3-S3, 20.4R3-S4, 21.1R2, 21.2R2, 21.3R2, 21.4R1
Junos OS Evolved - addressed in versions 20.4R3-S4-EVO, 21.2R2-EVO, 21.3R2-EVO, 21.4R1-EVO
Junos OS Evolved - addressed in versions 20.4R3-S4-EVO, 21.2R2-EVO, 21.3R2-EVO, 21.4R1-EVO