CVE-2024-39528: Junos OS and Junos OS Evolved: Concurrent deletion of a routing-instance and receipt of an SNMP request cause an RPD crash
A Use After Free vulnerability in the Routing Protocol Daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an authenticated, network-based attacker to cause a Denial of Service (DoS).On all Junos OS and Junos Evolved platforms, if a routing-instance deactivation is triggered, and at the same time a specific SNMP request is received, a segmentation fault occurs which causes rpd to crash and restart.
This issue affects:
Junos OS:
All versions before 21.2R3-S8, 21.4 versions before 21.4R3-S5, 22.2 versions before 22.2R3-S3, 22.3 versions before 22.3R3-S2, 22.4 versions before 22.4R3, 23.2 versions before 23.2R2.
Junos OS Evolved:
All versions before 21.2R3-S8-EVO, 21.4-EVO versions before 21.4R3-S5-EVO, 22.2-EVO versions before 22.2R3-S3-EVO, 22.3-EVO versions before 22.3R3-S2-EVO, 22.4-EVO versions before 22.4R3-EVO, 23.2-EVO versions before 23.2R2-EVO.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-39528?
CVE-2024-39528 has a severity rating that allows authenticated network-based attackers to cause Denial of Service (DoS).
How do I fix CVE-2024-39528?
To address CVE-2024-39528, you should upgrade to the latest patched version of Junos OS or Junos OS Evolved as recommended by Juniper Networks.
What versions of Junos OS are affected by CVE-2024-39528?
CVE-2024-39528 affects multiple versions of Junos OS, specifically those up to version 21.2 but not including later versions.
Is CVE-2024-39528 remotely exploitable?
Yes, CVE-2024-39528 is remotely exploitable by authenticated attackers on the network.
What type of vulnerability is CVE-2024-39528?
CVE-2024-39528 is categorized as a Use After Free vulnerability in the Routing Protocol Daemon (rpd) of the affected systems.