#VU94337 Missing release of memory after effective lifetime in Juniper Junos OS and Junos OS Evolved - CVE-2024-39549
Published: July 15, 2024
Juniper Junos OS
Junos OS Evolved
Juniper Networks, Inc.
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to missing release of memory after effective lifetime error in the routing process daemon (rpd). A remote non-authenticated attacker can send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute.