CVE-2021-0230: Junos OS: SRX Series: Memory leak when querying Aggregated Ethernet (AE) interface statistics
On Juniper Networks SRX Series devices with link aggregation (lag) configured, executing any operation that fetches Aggregated Ethernet (AE) interface statistics, including but not limited to SNMP GET requests, causes a slow kernel memory leak. If all the available memory is consumed, the traffic will be impacted and a reboot might be required. The following log can be seen if this issue happens. /kernel: rtpfeveto: Memory over consumed. Op 1 err 12, rtsmid 0:-1, msg type 72 /kernel: rtpfeveto: free kmemmap memory = (20770816) curproc = kmd An administrator can use the following CLI command to monitor the status of memory consumption (ifstat bucket): user@device > show system virtual-memory no-forwarding | match ifstat Type InUse MemUse HighUse Limit Requests Limit Limit Size(s) ifstat 2588977 162708K - 19633958 <<<< user@device > show system virtual-memory no-forwarding | match ifstat Type InUse MemUse HighUse Limit Requests Limit Limit Size(s) ifstat 3021629 189749K - 22914415 <<<< This issue affects Juniper Networks Junos OS on SRX Series: 17.1 versions 17.1R3 and above prior to 17.3R3-S11; 17.4 versions prior to 17.4R3-S5; 18.2 versions prior to 18.2R3-S7, 18.2R3-S8; 18.3 versions prior to 18.3R3-S4; 18.4 versions prior to 18.4R2-S7, 18.4R3-S6; 19.1 versions prior to 19.1R3-S4; 19.2 versions prior to 19.2R1-S6; 19.3 versions prior to 19.3R3-S1; 19.4 versions prior to 19.4R3-S1; 20.1 versions prior to 20.1R2, 20.1R3; 20.2 versions prior to 20.2R2-S2, 20.2R3; 20.3 versions prior to 20.3R1-S2, 20.3R2. This issue does not affect Juniper Networks Junos OS prior to 17.1R3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-0230?
CVE-2021-0230 is rated as a medium severity vulnerability in Juniper Networks devices.
How do I fix CVE-2021-0230?
To mitigate CVE-2021-0230, it is recommended to upgrade to a fixed version of Juniper JUNOS software as provided by the vendor.
What devices are affected by CVE-2021-0230?
CVE-2021-0230 affects Juniper Networks SRX Series devices configured with link aggregation.
What is the impact of CVE-2021-0230?
The impact of CVE-2021-0230 includes a slow kernel memory leak when fetching Aggregated Ethernet interface statistics, potentially leading to resource exhaustion.
Are there any workarounds for CVE-2021-0230?
There are no specific workarounds for CVE-2021-0230; applying software updates is the primary recommendation.