Memory leak in Junos OS - CVE-2022-22204

 

Memory leak in Junos OS - CVE-2022-22204

Published: July 13, 2022


Vulnerability identifier: #VU82495
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-22204
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

An Improper Release of Memory Before Removing Last Reference vulnerability in the Session Initiation Protocol (SIP) Application Layer Gateway (ALG) of Juniper Networks Junos OS allows unauthenticated network based attacker to cause a partial Denial of Service (DoS).

 On all MX and SRX platforms, if the SIP ALG is enabled, receipt of a specific SIP packet will create a stale SIP entry.


Affected software

Junos OS

How to mitigate CVE-2022-22204

Install updates from vendor's website.

Junos OS - addressed in versions 20.4R3-S2, 21.1R3-S2, 21.2R2-S2, 21.2R3, 21.3R2, 21.4R2, 22.1R1

External References

Related Security Bulletins