CVE-2022-22173: Junos OS: CRL failing to download causes a memory leak and ultimately a DoS
A Missing Release of Memory after Effective Lifetime vulnerability in the Public Key Infrastructure daemon (pkid) of Juniper Networks Junos OS allows an unauthenticated networked attacker to cause Denial of Service (DoS). In a scenario where Public Key Infrastructure (PKI) is used in combination with Certificate Revocation List (CRL), if the CRL fails to download the memory allocated to store the CRL is not released. Repeated occurrences will eventually consume all available memory and lead to an inoperable state of the affected system causing a DoS. This issue affects Juniper Networks Junos OS: All versions prior to 18.3R3-S6; 18.4 versions prior to 18.4R2-S9, 18.4R3-S10; 19.1 versions prior to 19.1R2-S3, 19.1R3-S7; 19.2 versions prior to 19.2R1-S8, 19.2R3-S4; 19.3 versions prior to 19.3R3-S4; 19.4 versions prior to 19.4R2-S5, 19.4R3-S5; 20.1 versions prior to 20.1R3-S1; 20.2 versions prior to 20.2R3-S2; 20.3 versions prior to 20.3R3-S1; 20.4 versions prior to 20.4R3; 21.1 versions prior to 21.1R2, 21.1R3; 21.2 versions prior to 21.2R1-S1, 21.2R2. This issue can be observed by monitoring the memory utilization of the pkid process via: root@jtac-srx1500-r2003> show system processes extensive | match pki 20931 root 20 0 733M 14352K select 0:00 0.00% pkid which increases over time: root@jtac-srx1500-r2003> show system processes extensive | match pki 22587 root 20 0 901M 181M select 0:03 0.00% pkid
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-22173?
CVE-2022-22173 has a severity score that allows unauthenticated attackers to cause a Denial of Service (DoS) in affected Juniper Junos OS versions.
How do I fix CVE-2022-22173?
To mitigate CVE-2022-22173, it is recommended to upgrade to the patched versions of Juniper Junos OS that address this vulnerability.
Which versions of Junos OS are affected by CVE-2022-22173?
CVE-2022-22173 affects Juniper Junos OS versions up to and including 18.3.
What type of attack can CVE-2022-22173 enable?
CVE-2022-22173 allows unauthenticated networked attackers to execute a Denial of Service (DoS) attack against the affected devices.
Is there a known workaround for CVE-2022-22173?
There are currently no documented workarounds for CVE-2022-22173, making upgrading to a patched version the best course of action.