Use-after-free in Junos OS Evolved and Junos OS - CVE-2024-39528
Published: July 12, 2024
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to use after free error in the Routing Protocol Daemon (rpd). A remote user can cause a denial of service (DoS) attack.
On all Junos OS and Junos Evolved platforms, if a routing-instance deactivation is triggered, and at the same time a specific SNMP request is received, a segmentation fault occurs which causes rpd to crash and restart.
Affected software
Junos OS
How to mitigate CVE-2024-39528
Junos OS - addressed in versions 21.2R3-S8, 21.4R3-S5, 22.2R3-S3, 22.3R3-S2, 22.4R3, 23.2R2, 23.4R1