An Out-of-Bounds Write vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, network-based attacker to cause a Denial of Service (DoS).
On all Junos OS and Junos OS Evolved devices an rpd crash and restart can occur while processing BGP route updates received over an established BGP session. This specific issue is observed for BGP routes learned via a peer which is configured with a BGP import policy that has hundreds of terms matching IPv4 and/or IPv6 prefixes.
This issue affects Juniper Networks Junos OS:
This issue affects Juniper Networks Junos OS Evolved:
| Software | From | Fixed in |
|---|---|---|
| juniper / junos | 20.4-r1 | 20.4-r1.x |
| juniper / junos_os_evolved | 20.4-r1 | 20.4-r1.x |
| juniper / junos | 20.4-r1-s1 | 20.4-r1-s1.x |
| juniper / junos | 21.1-r1 | 21.1-r1.x |
| juniper / junos | 20.4-r2 | 20.4-r2.x |
| juniper / junos | 21.2-r1 | 21.2-r1.x |
| juniper / junos | 20.4-r2-s1 | 20.4-r2-s1.x |
| juniper / junos | 21.1-r1-s1 | 21.1-r1-s1.x |
| juniper / junos_os_evolved | 21.1-r1 | 21.1-r1.x |
| juniper / junos_os_evolved | 21.1-r2 | 21.1-r2.x |
| juniper / junos_os_evolved | 21.1-r1-s1 | 21.1-r1-s1.x |
| juniper / junos_os_evolved | 21.2-r1 | 21.2-r1.x |
| juniper / junos_os_evolved | 21.2-r1-s1 | 21.2-r1-s1.x |
| juniper / junos_os_evolved | 21.2-r2 | 21.2-r2.x |
| juniper / junos_os_evolved | 20.4-r1-s1 | 20.4-r1-s1.x |
| juniper / junos_os_evolved | 20.4-r1-s2 | 20.4-r1-s2.x |
| juniper / junos_os_evolved | 20.4-r2 | 20.4-r2.x |
| juniper / junos_os_evolved | 20.4-r2-s1 | 20.4-r2-s1.x |
| juniper / junos_os_evolved | 20.4-r2-s2 | 20.4-r2-s2.x |
| juniper / junos_os_evolved | 20.4-r2-s3 | 20.4-r2-s3.x |
| juniper / junos_os_evolved | 20.4-r3 | 20.4-r3.x |
| juniper / junos_os_evolved | 20.4-r3-s1 | 20.4-r3-s1.x |
| juniper / junos | 21.2-r1-s1 | 21.2-r1-s1.x |
| juniper / junos | 21.1-r2 | 21.1-r2.x |
| juniper / junos | 20.4-r3 | 20.4-r3.x |
| juniper / junos_os_evolved | 21.3-r1 | 21.3-r1.x |
| juniper / junos | 21.3-r1 | 21.3-r1.x |
| juniper / junos | 21.3-r2 | 21.3-r2.x |
| juniper / junos | 21.2-r2 | 21.2-r2.x |
| juniper / junos | 20.4-r3-s1 | 20.4-r3-s1.x |
| juniper / junos | 20.4-r2-s2 | 20.4-r2-s2.x |
| juniper / junos | 21.1-r3 | 21.1-r3.x |
| juniper / junos | 21.1-r2-s1 | 21.1-r2-s1.x |
| juniper / junos | 21.2 | 21.2.x |
| juniper / junos | 20.4 | 20.4.x |
| juniper / junos_os_evolved | 20.4 | 20.4.x |
| juniper / junos_os_evolved | 21.2 | 21.2.x |
| juniper / junos_os_evolved | 21.2-r1-s2 | 21.2-r1-s2.x |
| juniper / junos_os_evolved | 21.2-r2-s1 | 21.2-r2-s1.x |
| juniper / junos_os_evolved | 21.3-r1-s1 | 21.3-r1-s1.x |
| juniper / junos | 21.1-r2-s2 | 21.1-r2-s2.x |
| juniper / junos | 21.2-r1-s2 | 21.2-r1-s2.x |
| juniper / junos | 21.2-r2-s1 | 21.2-r2-s1.x |
| juniper / junos | 21.2-r2-s2 | 21.2-r2-s2.x |
| juniper / junos | 21.4-r1-s1 | 21.4-r1-s1.x |
| juniper / junos | 21.3-r1-s1 | 21.3-r1-s1.x |
| juniper / junos | 21.3-r1-s2 | 21.3-r1-s2.x |
| juniper / junos | 21.4-r1 | 21.4-r1.x |
| juniper / junos_os_evolved | - | 20.4 |
| juniper / junos_os_evolved | 20.4-r3-s2 | 20.4-r3-s2.x |
| juniper / junos_os_evolved | 21.4-r1 | 21.4-r1.x |
| juniper / junos_os_evolved | 21.4-r1-s1 | 21.4-r1-s1.x |
| juniper / junos_os_evolved | 21.2-r2-s2 | 21.2-r2-s2.x |
| juniper / junos_os_evolved | 21.1-r3 | 21.1-r3.x |
| juniper / junos | 21.3-r2-s1 | 21.3-r2-s1.x |
| juniper / junos | 21.3-r2-s2 | 21.3-r2-s2.x |
| juniper / junos | 21.4-r1-s2 | 21.4-r1-s2.x |
| juniper / junos | 20.4-r3-s2 | 20.4-r3-s2.x |
| juniper / junos | 21.1-r3-s1 | 21.1-r3-s1.x |
| juniper / junos | 21.2-r3 | 21.2-r3.x |
| juniper / junos | 21.3-r3 | 21.3-r3.x |
| juniper / junos | 21.3-r3-s1 | 21.3-r3-s1.x |
| juniper / junos | 21.4-r2 | 21.4-r2.x |
| juniper / junos | 20.4-r3-s3 | 20.4-r3-s3.x |
| juniper / junos_os_evolved | 21.2-r3 | 21.2-r3.x |
| juniper / junos_os_evolved | 21.3-r2 | 21.3-r2.x |
| juniper / junos | 21.4 | 21.4.x |
| juniper / junos | 21.3 | 21.3.x |
| juniper / junos_os_evolved | 21.4 | 21.4.x |
| juniper / junos | 21.1-r3-s2 | 21.1-r3-s2.x |
| juniper / junos_os_evolved | 21.1-r3-s1 | 21.1-r3-s1.x |
| juniper / junos | 21.4-r3 | 21.4-r3.x |
| juniper / junos_os_evolved | 20.4-r3-s4 | 20.4-r3-s4.x |
| juniper / junos_os_evolved | 20.4-r3-s3 | 20.4-r3-s3.x |
| juniper / junos_os_evolved | 21.3-r2-s1 | 21.3-r2-s1.x |
| juniper / junos_os_evolved | 21.3-r2-s2 | 21.3-r2-s2.x |
| juniper / junos_os_evolved | 21.4-r2 | 21.4-r2.x |
| juniper / junos_os_evolved | 21.4-r1-s2 | 21.4-r1-s2.x |
| juniper / junos | 20.4-r3-s4 | 20.4-r3-s4.x |
| juniper / junos_os_evolved | 21.2-r3-s1 | 21.2-r3-s1.x |
| juniper / junos_os_evolved | 21.3-r3 | 21.3-r3.x |
| juniper / junos_os_evolved | 20.4-r3-s5 | 20.4-r3-s5.x |
| juniper / junos | 21.2-r3-s1 | 21.2-r3-s1.x |
| juniper / junos | 21.1-r3-s3 | 21.1-r3-s3.x |
| juniper / junos_os_evolved | 21.4-r3 | 21.4-r3.x |
| juniper / junos | 21.1-r3-s4 | 21.1-r3-s4.x |
| juniper / junos | 21.3-r3-s2 | 21.3-r3-s2.x |
| juniper / junos | 20.4-r3-s5 | 20.4-r3-s5.x |
| juniper / junos | - | 20.4 |
| juniper / junos | 21.4-r3-s1 | 21.4-r3-s1.x |
| juniper / junos | 21.3-r3-s3 | 21.3-r3-s3.x |
| juniper / junos | 21.4-r3-s2 | 21.4-r3-s2.x |
| juniper / junos_os_evolved | 21.1-r3-s2 | 21.1-r3-s2.x |
| juniper / junos_os_evolved | 21.1-r3-s3 | 21.1-r3-s3.x |
| juniper / junos | 20.4-r3-s6 | 20.4-r3-s6.x |
| juniper / junos_os_evolved | 21.4-r3-s1 | 21.4-r3-s1.x |
| juniper / junos_os_evolved | 21.4-r3-s2 | 21.4-r3-s2.x |
| juniper / junos_os_evolved | 21.4-r3-s3 | 21.4-r3-s3.x |
| juniper / junos_os_evolved | 20.4-r3-s6 | 20.4-r3-s6.x |
| juniper / junos_os_evolved | 21.3-r3-s1 | 21.3-r3-s1.x |
| juniper / junos_os_evolved | 21.3-r3-s2 | 21.3-r3-s2.x |
| juniper / junos_os_evolved | 21.3-r3-s3 | 21.3-r3-s3.x |
| juniper / junos | 21.3-r3-s4 | 21.3-r3-s4.x |
| juniper / junos | 21.4-r3-s3 | 21.4-r3-s3.x |
| juniper / junos | 20.4-r3-s7 | 20.4-r3-s7.x |
| juniper / junos | 21.1-r3-s5 | 21.1-r3-s5.x |
| juniper / junos_os_evolved | 21.3-r3-s4 | 21.3-r3-s4.x |
| juniper / junos_os_evolved | 20.4-r3-s7 | 20.4-r3-s7.x |
| juniper / junos | 21.4-r3-s4 | 21.4-r3-s4.x |
| juniper / junos_os_evolved | 21.4-r3-s4 | 21.4-r3-s4.x |