CVE-2023-22392: Junos OS: PTX Series and QFX10000 Series: Received flow-routes which aren't installed as the hardware doesn't support them, lead to an FPC heap memory leak
A Missing Release of Memory after Effective Lifetime vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an adjacent, unauthenticated attacker to cause a Denial of Service (DoS).
PTX3000, PTX5000, QFX10000, PTX1000, PTX10002, and PTX10004, PTX10008 and PTX10016 with LC110x FPCs do not support certain flow-routes. Once a flow-route is received over an established BGP session and an attempt is made to install the resulting filter into the PFE, FPC heap memory is leaked. The FPC heap memory can be monitored using the CLI command "show chassis fpc".
The following syslog messages can be observed if the respective filter derived from a flow-route cannot be installed.
exprdfwsfmrangeadd:661 SFM packet-length Unable to get a sfm entry for updating the hw exprdfwhwsfmadd:750 Unable to add the filter secondarymatch to the hardware exprdfwbasehwadd:52 Failed to add h/w sfm data. exprdfwbasehwcreate:114 Failed to add h/w data. exprdfwbasepfeinstcreate:241 Failed to create base inst for sfilter 0 on PFE 0 for flowspecdefaultinet exprdfwfltinstchange:1368 Failed to create flowspecdefaultinet on PFE 0 exprdfwhwpgmfnum:465 dfwpfeinstold not found for pfeindex 0! exprdfwbppgmfltnum:548 Failed to pgm bind-point in hw: generic failure exprdfwbptopohandler:1102 Failed to program fnum. exprdfwentryprocesschange:679 Failed to change instance for filter flowspecdefaultinet. This issue affects Juniper Networks Junos OS:
on PTX1000, PTX10002, and PTX10004, PTX10008 and PTX10016 with LC110x FPCs:
All versions prior to 20.4R3-S5; 21.1 versions prior to 21.1R3-S4; 21.2 versions prior to 21.2R3-S2; 21.3 versions prior to 21.3R3; 21.4 versions prior to 21.4R2-S2, 21.4R3; 22.1 versions prior to 22.1R1-S2, 22.1R2.
on PTX3000, PTX5000, QFX10000:
All versions prior to 20.4R3-S8; 21.1 version 21.1R1 and later versions; 21.2 versions prior to 21.2R3-S6; 21.3 versions prior to 21.3R3-S5; 21.4 versions prior to 21.4R3-S4; 22.1 versions prior to 22.1R3-S3 22.2 versions prior to 22.2R3-S1 22.3 versions prior to 22.3R2-S2, 22.3R3 22.4 versions prior to 22.4R2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2023-22392?
CVE-2023-22392 has a medium severity rating allowing unauthorized denial of service attacks.
How do I fix CVE-2023-22392?
To fix CVE-2023-22392, upgrade to Junos OS version 20.4-r3 or later, or the appropriate patched version of 21.1, 21.2, or 21.3.
What devices are affected by CVE-2023-22392?
CVE-2023-22392 impacts devices running Juniper Networks Junos OS versions up to 20.4, including PTX and QFX series.
Can CVE-2023-22392 be exploited remotely?
Yes, CVE-2023-22392 can be exploited remotely by an adjacent, unauthenticated attacker.
What is the nature of the CVE-2023-22392 vulnerability?
CVE-2023-22392 is a missing release of memory after effective lifetime vulnerability that causes denial of service.