Missing release of memory after effective lifetime in Junos OS Evolved and Junos OS - CVE-2024-39549
Published: July 15, 2024
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to missing release of memory after effective lifetime error in the routing process daemon (rpd). A remote non-authenticated attacker can send a malformed BGP Path attribute update which allocates memory used to log the bad path attribute.
Affected software
Junos OS
How to mitigate CVE-2024-39549
Junos OS - addressed in versions 21.2R3-S8, 22.2R3-S4, 22.3R3-S3, 22.4R3-S3, 23.2R2-S1, 23.4R1-S2, 23.4R2, 24.2R1