#VU85301 Missing release of memory after effective lifetime in Juniper Junos OS - CVE-2024-21599
Published: January 11, 2024
Juniper Junos OS
Juniper Networks, Inc.
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to missing release of memory after effective lifetime error in the Packet Forwarding Engine (PFE). A remote non-authenticated attacker can cause a Denial of Service (DoS).
If an MX Series device receives PTP packets on an MPC3E that doesn't support PTP this causes a memory leak which will result in unpredictable behavior and ultimately in an MPC crash and restart.
To monitor for this issue, please use the following FPC vty level commands: show heap shows an increase in "LAN buffer" utilization and show clksync ptp nbr-upd-info shows non-zero "Pending PFEs" counter.