Memory leak in Junos OS and Junos OS Evolved - CVE-2022-22240
Published: October 12, 2022
Vulnerability details
The vulnerability allows a local authenticated user to perform a denial of service (DoS) attack.
An Allocation of Resources Without Limits or Throttling and a Missing Release of Memory after Effective Lifetime vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows a locally authenticated low privileged attacker to cause a Denial of Sevice (DoS).
In a high-scaled BGP routing environment with rib-sharding enabled, two issues may occur when executing a specific CLI command.
Affected software
Junos OS Evolved
How to mitigate CVE-2022-22240
Junos OS Evolved - addressed in versions 20.4R3-S1-EVO, 21.2R1-S2-EVO, 21.2R3-EVO, 21.3R2-EVO, 21.4R1-EVO