A Missing Release of Resource after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause a Denial of Service (DoS) by sending specific packets over VXLAN which cause heap memory to leak and on exhaustion the PFE to reset. The heap memory utilization can be monitored with the command: user@host> show chassis fpc This issue affects: Juniper Networks Junos OS 19.4 versions prior to 19.4R2-S6, 19.4R3-S6; 20.1 versions prior to 20.1R3-S2; 20.2 versions prior to 20.2R3-S3; 20.3 versions prior to 20.3R3-S1; 20.4 versions prior to 20.4R3; 21.1 versions prior to 21.1R3; 21.2 versions prior to 21.2R2. This issue does not affect versions of Junos OS prior to 19.4R1.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://kb.juniper.net/JSA11277 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: juniper
Published: 2022-01-19T00:21:17.254985Z
Updated: 2024-09-17T04:23:57.528Z
Reserved: 2021-12-21T00:00:00
Link: CVE-2022-22170
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-01-19T01:15:09.080
Modified: 2024-11-21T06:46:18.477
Link: CVE-2022-22170
Redhat
No data.