CVE-2022-22155: Junos OS: ACX5448: FPC memory leak due to IPv6 neighbor flaps
An Uncontrolled Resource Consumption vulnerability in the handling of IPv6 neighbor state change events in Juniper Networks Junos OS allows an adjacent attacker to cause a memory leak in the Flexible PIC Concentrator (FPC) of an ACX5448 router. The continuous flapping of an IPv6 neighbor with specific timing will cause the FPC to run out of resources, leading to a Denial of Service (DoS) condition. Once the condition occurs, further packet processing will be impacted, creating a sustained Denial of Service (DoS) condition, requiring a manual PFE restart to restore service. The following error messages will be seen after the FPC resources have been exhausted: fpc0 DNXNH::dnxnhtagipv4hwinstall(),3135: dnxnhtagipv4hwinstall: BCM L3 Egress create object failed for NH 602 (-14:No resources for operation), BCM NH Params: unit:0 Port:41, L3INTF:0 Flags: 0x40 fpc0 DNXNH::dnxnhtagipv4hwinstall(),3135: dnxnhtagipv4hwinstall: BCM L3 Egress create object failed for NH 602 (-14:No resources for operation), BCM NH Params: unit:0 Port:41, L3INTF:0 Flags: 0x40 fpc0 DNXNH::dnxnhtagipv4hwinstall(),3135: dnxnhtagipv4hwinstall: BCM L3 Egress create object failed for NH 602 (-14:No resources for operation), BCM NH Params: unit:0 Port:41, L3INTF:0 Flags: 0x40 fpc0 DNXNH::dnxnhtagipv4hwinstall(),3135: dnxnhtagipv4hwinstall: BCM L3 Egress create object failed for NH 602 (-14:No resources for operation), BCM NH Params: unit:0 Port:41, L3INTF:0 Flags: 0x40 This issue only affects the ACX5448 router. No other products or platforms are affected by this vulnerability. This issue affects Juniper Networks Junos OS on ACX5448: 18.4 versions prior to 18.4R3-S10; 19.1 versions prior to 19.1R3-S5; 19.2 versions prior to 19.2R1-S8, 19.2R3-S2; 19.3 versions prior to 19.3R2-S6, 19.3R3-S2; 19.4 versions prior to 19.4R1-S3, 19.4R2-S2, 19.4R3; 20.1 versions prior to 20.1R2; 20.2 versions prior to 20.2R1-S1, 20.2R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22155?
CVE-2022-22155 has been classified as a high-severity vulnerability due to its potential to cause a memory leak affecting the Flexible PIC Concentrator.
How do I fix CVE-2022-22155?
To mitigate CVE-2022-22155, you should upgrade your Junos OS to the patched versions specified in the vendor's advisory.
Which versions of Junos OS are affected by CVE-2022-22155?
CVE-2022-22155 affects specific versions of Junos OS including 18.4, 19.1, 19.2, 19.3, 19.4, and 20.1.
What kind of attacks can exploit CVE-2022-22155?
An adjacent attacker can exploit CVE-2022-22155 by continuously flapping an IPv6 neighbor state, leading to resource exhaustion.
Is there a workaround for CVE-2022-22155?
Currently, the recommended action is to upgrade to a secure version since no workaround to fully mitigate the vulnerability has been provided.