CVE-2024-21613: Junos OS and Junos OS Evolved: A link flap causes patroot memory leak which leads to rpd crash

Published Jan 12, 2024
·
Updated

A Missing Release of Memory after Effective Lifetime vulnerability in Routing Protocol Daemon (RPD) of Juniper Networks Junos OS and Junos OS Evolved allows an unauthenticated, adjacent attacker to cause an rpd crash, leading to Denial of Service (DoS).

On all Junos OS and Junos OS Evolved platforms, when traffic engineering is enabled for OSPF or ISIS, and a link flaps, a patroot memory leak is observed. This memory leak, over time, will lead to an rpd crash and restart.

The memory usage can be monitored using the below command.

user@host> show task memory detail | match patroot This issue affects:

Juniper Networks Junos OS

All versions earlier than 21.2R3-S3; 21.3 versions earlier than 21.3R3-S5; 21.4 versions earlier than 21.4R3-S3; 22.1 versions earlier than 22.1R3; 22.2 versions earlier than 22.2R3.

Juniper Networks Junos OS Evolved

All versions earlier than 21.3R3-S5-EVO; 21.4 versions earlier than 21.4R3-EVO; 22.1 versions earlier than 22.1R3-EVO; 22.2 versions earlier than 22.2R3-EVO.

Affected Software

76 affected components
Juniper JUNOS=21.2
Juniper JUNOS=21.2-r1
Juniper JUNOS=21.2-r1-s1
Juniper JUNOS=21.2-r1-s2
Juniper JUNOS=21.2-r2
Juniper JUNOS=21.2-r2-s1
Juniper JUNOS=21.2-r2-s2
Juniper JUNOS=21.2-r3
Juniper JUNOS=21.2-r3-s1
Juniper JUNOS=21.2-r3-s2
Juniper JUNOS=21.3
Juniper JUNOS=21.3-r1
Juniper JUNOS=21.3-r1-s1
Juniper JUNOS=21.3-r1-s2
Juniper JUNOS=21.3-r2
Juniper JUNOS=21.3-r2-s1
Juniper JUNOS=21.3-r2-s2
Juniper JUNOS=21.3-r3
Juniper JUNOS=21.3-r3-s1
Juniper JUNOS=21.3-r3-s2
Juniper JUNOS=21.3-r3-s3
Juniper JUNOS=21.3-r3-s4
Juniper JUNOS=21.4
Juniper JUNOS=21.4-r1
Juniper JUNOS=21.4-r1-s1
Juniper JUNOS=21.4-r1-s2
Juniper JUNOS=21.4-r2
Juniper JUNOS=21.4-r2-s1
Juniper JUNOS=21.4-r2-s2
Juniper JUNOS=21.4-r3
Juniper JUNOS=21.4-r3-s1
Juniper JUNOS=21.4-r3-s2
Juniper JUNOS=22.1
Juniper JUNOS=22.1-r1
Juniper JUNOS=22.1-r1-s1
Juniper JUNOS=22.1-r1-s2
Juniper JUNOS=22.1-r2
Juniper JUNOS=22.1-r2-s1
Juniper JUNOS=22.1-r2-s2
Juniper JUNOS=22.2
Juniper JUNOS=22.2-r1
Juniper JUNOS=22.2-r1-s1
Juniper JUNOS=22.2-r1-s2
Juniper JUNOS=22.2-r2
Juniper JUNOS=22.2-r2-s1
Juniper JUNOS=22.2-r2-s2
Juniper Junos OS Evolved=21.3
Juniper Junos OS Evolved=21.3-r1
Juniper Junos OS Evolved=21.3-r1-s1
Juniper Junos OS Evolved=21.3-r2
Juniper Junos OS Evolved=21.3-r2-s1
Juniper Junos OS Evolved=21.3-r2-s2
Juniper Junos OS Evolved=21.3-r3
Juniper Junos OS Evolved=21.3-r3-s1
Juniper Junos OS Evolved=21.3-r3-s2
Juniper Junos OS Evolved=21.3-r3-s3
Juniper Junos OS Evolved=21.3-r3-s4
Juniper Junos OS Evolved=21.4
Juniper Junos OS Evolved=21.4-r1
Juniper Junos OS Evolved=21.4-r1-s1
Juniper Junos OS Evolved=21.4-r1-s2
Juniper Junos OS Evolved=21.4-r2
Juniper Junos OS Evolved=21.4-r2-s1
Juniper Junos OS Evolved=21.4-r2-s2
Juniper Junos OS Evolved=22.1
Juniper Junos OS Evolved=22.1-r1
Juniper Junos OS Evolved=22.1-r1-s1
Juniper Junos OS Evolved=22.1-r1-s2
Juniper Junos OS Evolved=22.1-r2
Juniper Junos OS Evolved=22.1-r2-s1
Juniper Junos OS Evolved=22.2
Juniper Junos OS Evolved=22.2-r1
Juniper Junos OS Evolved=22.2-r1-s1
Juniper Junos OS Evolved=22.2-r2
Juniper Junos OS Evolved=22.2-r2-s1
Juniper Junos OS Evolved=22.2-r2-s2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Juniper Networks Junos OS / Junos OS Evolved (Routing Protocol Daemon rpd) to a version that resolves this vulnerability.

    Fixed in 21.3R3-S5-EVO
  2. Upgrade

    Upgrade Juniper Networks Junos OS / Junos OS Evolved (Routing Protocol Daemon rpd) to a version that resolves this vulnerability.

    Fixed in 21.4R3-EVO
  3. Upgrade

    Upgrade Juniper Networks Junos OS / Junos OS Evolved (Routing Protocol Daemon rpd) to a version that resolves this vulnerability.

    Fixed in 21.4R3-S3
  4. Upgrade

    Upgrade Juniper Networks Junos OS / Junos OS Evolved (Routing Protocol Daemon rpd) to a version that resolves this vulnerability.

    Fixed in 22.1R3-EVO
  5. Upgrade

    Upgrade Juniper Networks Junos OS / Junos OS Evolved (Routing Protocol Daemon rpd) to a version that resolves this vulnerability.

    Fixed in 22.1R3
  6. Upgrade

    Upgrade Juniper Networks Junos OS / Junos OS Evolved (Routing Protocol Daemon rpd) to a version that resolves this vulnerability.

    Fixed in 22.2R3-EVO
  7. Upgrade

    Upgrade Juniper Networks Junos OS / Junos OS Evolved (Routing Protocol Daemon rpd) to a version that resolves this vulnerability.

    Fixed in 22.2R3
  8. Upgrade

    Upgrade Juniper Networks Junos OS / Junos OS Evolved (Routing Protocol Daemon rpd) to a version that resolves this vulnerability.

    Fixed in 21.2R3-S3
  9. Configuration

    If not required, disable traffic engineering for OSPF or ISIS to avoid patroot memory leak observed when traffic engineering is enabled and a link flaps.

    Traffic engineering for OSPF/ISIS (RPD path) traffic engineering enabled for OSPF or ISIS = disabled
  10. Operational

    Monitor memory usage on affected Junos OS / Junos OS Evolved platforms using: "show task memory detail | match patroot" to observe the patroot memory leak leading to an rpd crash and restart.

Event History

Jan 12, 2024
CVE Published
via MITRE·12:55 AM
Data Sourced
via MITRE·12:55 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2024-21613?

CVE-2024-21613 has a high severity rating due to its potential to cause Denial of Service by crashing the Routing Protocol Daemon.

2

How do I fix CVE-2024-21613?

To fix CVE-2024-21613, you must upgrade to the patched versions of Junos OS as specified in the advisory.

3

Which versions of Junos OS are affected by CVE-2024-21613?

CVE-2024-21613 affects Junos OS versions 21.2 through 22.2.

4

What kind of attack does CVE-2024-21613 facilitate?

CVE-2024-21613 allows an unauthenticated, adjacent attacker to execute a Denial of Service (DoS) attack.

5

Is CVE-2024-21613 exploitable remotely?

CVE-2024-21613 is not remotely exploitable, as it requires an adjacent attacker to perform the exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203