An Access of Uninitialized Pointer vulnerability in the routing protocol daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved with BGP sharding configured allows an attacker triggering indirect next-hop updates, along with timing outside the attacker's control, to cause rpd to crash and restart, leading to a Denial of Service (DoS).
With BGP sharding enabled, triggering route resolution of an indirect next-hop (e.g., an IGP route change over which a BGP route gets resolved), may cause rpd to crash and restart. An attacker causing continuous IGP route churn, resulting in repeated route re-resolution, will increase the likelihood of triggering this issue, leading to a potentially extended DoS condition.
This issue affects:
Junos OS:
Junos OS Evolved:
Versions before Junos OS 21.3R1 and Junos OS Evolved 21.3R1-EVO are unaffected by this issue.
| Software | From | Fixed in |
|---|---|---|
| juniper / junos | - | 21.4 |
| juniper / junos | 21.4 | 21.4.x |
| juniper / junos | 21.4-r1 | 21.4-r1.x |
| juniper / junos | 21.4-r1-s1 | 21.4-r1-s1.x |
| juniper / junos | 21.4-r1-s2 | 21.4-r1-s2.x |
| juniper / junos | 21.4-r2 | 21.4-r2.x |
| juniper / junos | 21.4-r2-s1 | 21.4-r2-s1.x |
| juniper / junos | 21.4-r2-s2 | 21.4-r2-s2.x |
| juniper / junos | 21.4-r3 | 21.4-r3.x |
| juniper / junos | 21.4-r3-s1 | 21.4-r3-s1.x |
| juniper / junos | 21.4-r3-s2 | 21.4-r3-s2.x |
| juniper / junos | 21.4-r3-s3 | 21.4-r3-s3.x |
| juniper / junos | 21.4-r3-s4 | 21.4-r3-s4.x |
| juniper / junos | 21.4-r3-s5 | 21.4-r3-s5.x |
| juniper / junos | 22.1 | 22.1.x |
| juniper / junos | 22.1-r1 | 22.1-r1.x |
| juniper / junos | 22.1-r1-s1 | 22.1-r1-s1.x |
| juniper / junos | 22.1-r1-s2 | 22.1-r1-s2.x |
| juniper / junos | 22.1-r2 | 22.1-r2.x |
| juniper / junos | 22.1-r2-s1 | 22.1-r2-s1.x |
| juniper / junos | 22.1-r2-s2 | 22.1-r2-s2.x |
| juniper / junos | 22.1-r3 | 22.1-r3.x |
| juniper / junos | 22.1-r3-s1 | 22.1-r3-s1.x |
| juniper / junos | 22.1-r3-s2 | 22.1-r3-s2.x |
| juniper / junos | 22.1-r3-s3 | 22.1-r3-s3.x |
| juniper / junos | 22.1-r3-s4 | 22.1-r3-s4.x |
| juniper / junos | 22.1-r3-s5 | 22.1-r3-s5.x |
| juniper / junos | 22.2 | 22.2.x |
| juniper / junos | 22.2-r1 | 22.2-r1.x |
| juniper / junos | 22.2-r1-s1 | 22.2-r1-s1.x |
| juniper / junos | 22.2-r1-s2 | 22.2-r1-s2.x |
| juniper / junos | 22.2-r2 | 22.2-r2.x |
| juniper / junos | 22.2-r2-s1 | 22.2-r2-s1.x |
| juniper / junos | 22.2-r2-s2 | 22.2-r2-s2.x |
| juniper / junos | 22.2-r3 | 22.2-r3.x |
| juniper / junos | 22.2-r3-s1 | 22.2-r3-s1.x |
| juniper / junos | 22.2-r3-s2 | 22.2-r3-s2.x |
| juniper / junos | 22.3 | 22.3.x |
| juniper / junos | 22.3-r1 | 22.3-r1.x |
| juniper / junos | 22.3-r1-s1 | 22.3-r1-s1.x |
| juniper / junos | 22.3-r1-s2 | 22.3-r1-s2.x |
| juniper / junos | 22.3-r2 | 22.3-r2.x |
| juniper / junos | 22.3-r2-s1 | 22.3-r2-s1.x |
| juniper / junos | 22.3-r2-s2 | 22.3-r2-s2.x |
| juniper / junos | 22.3-r3 | 22.3-r3.x |
| juniper / junos | 22.3-r3-s1 | 22.3-r3-s1.x |
| juniper / junos | 22.3-r3-s2 | 22.3-r3-s2.x |
| juniper / junos | 22.4 | 22.4.x |
| juniper / junos | 22.4-r1 | 22.4-r1.x |
| juniper / junos | 22.4-r1-s1 | 22.4-r1-s1.x |
| juniper / junos | 22.4-r1-s2 | 22.4-r1-s2.x |
| juniper / junos | 22.4-r2 | 22.4-r2.x |
| juniper / junos | 22.4-r2-s1 | 22.4-r2-s1.x |
| juniper / junos | 22.4-r2-s2 | 22.4-r2-s2.x |
| juniper / junos | 23.2 | 23.2.x |
| juniper / junos | 23.2-r1 | 23.2-r1.x |
| juniper / junos | 23.2-r1-s1 | 23.2-r1-s1.x |
| juniper / junos | 23.2-r1-s2 | 23.2-r1-s2.x |
| juniper / junos_os_evolved | - | 22.3 |
| juniper / junos_os_evolved | 22.3 | 22.3.x |
| juniper / junos_os_evolved | 22.3-r1 | 22.3-r1.x |
| juniper / junos_os_evolved | 22.3-r1-s1 | 22.3-r1-s1.x |
| juniper / junos_os_evolved | 22.3-r1-s2 | 22.3-r1-s2.x |
| juniper / junos_os_evolved | 22.3-r2 | 22.3-r2.x |
| juniper / junos_os_evolved | 22.3-r2-s1 | 22.3-r2-s1.x |
| juniper / junos_os_evolved | 22.3-r2-s2 | 22.3-r2-s2.x |
| juniper / junos_os_evolved | 22.3-r3 | 22.3-r3.x |
| juniper / junos_os_evolved | 22.3-r3-s1 | 22.3-r3-s1.x |
| juniper / junos_os_evolved | 22.3-r3-s2 | 22.3-r3-s2.x |
| juniper / junos_os_evolved | 22.4 | 22.4.x |
| juniper / junos_os_evolved | 22.4-r1 | 22.4-r1.x |
| juniper / junos_os_evolved | 22.4-r1-s1 | 22.4-r1-s1.x |
| juniper / junos_os_evolved | 22.4-r1-s2 | 22.4-r1-s2.x |
| juniper / junos_os_evolved | 22.4-r2 | 22.4-r2.x |
| juniper / junos_os_evolved | 22.4-r2-s1 | 22.4-r2-s1.x |
| juniper / junos_os_evolved | 22.4-r2-s2 | 22.4-r2-s2.x |
| juniper / junos_os_evolved | 23.2 | 23.2.x |
| juniper / junos_os_evolved | 23.2-r1 | 23.2-r1.x |
| juniper / junos_os_evolved | 23.2-r1-s1 | 23.2-r1-s1.x |
| juniper / junos_os_evolved | 23.2-r1-s2 | 23.2-r1-s2.x |