CVE-2023-36831: Junos OS: SRX Series: jbuf memory leak when SSL Proxy and UTM Web-Filtering is applied
An Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, eventually leading to a Denial of Service (DoS) condition. Service restoration is only possible by rebooting the system.
The jbuf memory leak only occurs in SSL Proxy and UTM Web-Filtering configurations. Other products, platforms, and configurations are not affected by this vulnerability.
This issue affects Juniper Networks Junos OS on SRX Series: 22.2 versions prior to 22.2R3; 22.3 versions prior to 22.3R2-S1, 22.3R3; 22.4 versions prior to 22.4R1-S2, 22.4R2.
This issue does not affect Juniper Networks Junos OS versions prior to 22.2R2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.2R3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.3R2-S1 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.3R3 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.4R1-S2 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 22.4R2 - Upgrade
Upgrade
Juniper Networks Junos OS (SRX Series)to a version that resolves this vulnerability.Fixed in 23.1R1 - Compensating control
If SSL Proxy and UTM Web-Filtering are configured, temporarily disable or avoid those configurations, since the jbuf memory leak only occurs when SSL Proxy and UTM Web-Filtering is applied.
- Operational
For service restoration after a DoS condition caused by this issue, reboot the SRX system (service restoration is only possible by rebooting the system).
Event History
Frequently Asked Questions
What is CVE-2023-36831?
CVE-2023-36831 is an Improper Check or Handling of Exceptional Conditions vulnerability in the UTM (Unified Threat Management) Web-Filtering feature of Juniper Networks Junos OS on SRX Series.
How does CVE-2023-36831 affect Junos OS?
CVE-2023-36831 in Junos OS on SRX Series causes a jbuf memory leak to occur when accessing certain websites, leading to a Denial of Service (DoS) condition.
Which versions of Junos OS are affected by CVE-2023-36831?
Junos OS versions 22.2-r1, 22.2-r1-s1, 22.2-r1-s2, 22.2-r2, 22.2-r2-s1, 22.2-r2-s2, 22.3-r1, 22.3-r1-s1, 22.3-r1-s2, 22.3-r2, 22.4-r1, and 22.4-r1-s1 are affected by CVE-2023-36831.
What is the severity of CVE-2023-36831?
CVE-2023-36831 has a severity rating of high, with a severity value of 7.
How can I fix CVE-2023-36831?
To fix CVE-2023-36831, it is recommended to apply the necessary updates provided by Juniper Networks. Please refer to the Juniper Networks support portal for more information.