THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Fathom (Privacy friendly web analytics)
Zendesk (Helpdesk and Chat)

Ok

Home | EN
Support
CVE
PUBLISHED

CVE-2024-39550

Junos OS: MX Series with SPC3 line card: Port flaps causes rtlogd memory leak leading to Denial of Service

Assignerjuniper
Reserved2024-06-25
Published2024-07-11
Updated2024-07-11

Description

A Missing Release of Memory after Effective Lifetime vulnerability in the rtlogd process of Juniper Networks Junos OS on MX Series with SPC3 allows an unauthenticated, adjacent attacker to trigger internal events cause ( which can be done by repeated port flaps) to cause a slow memory leak, ultimately leading to a Denial of Service (DoS). Memory can only be recovered by manually restarting rtlogd process.  The memory usage can be monitored using the below command.     user@host> show system processes extensive | match rtlog  This issue affects Junos OS on MX Series with SPC3 line card:  * from 21.2R3 before 21.2R3-S8,  * from 21.4R2 before 21.4R3-S6,  * from 22.1 before 22.1R3-S5,  * from 22.2 before 22.2R3-S3,  * from 22.3 before 22.3R3-S2,  * from 22.4 before 22.4R3-S1,  * from 23.2 before 23.2R2,  * from 23.4 before 23.4R2.



MEDIUM: 6.5CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
HIGH: 7.1CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/R:U

Problem types

CWE-401 Missing Release of Memory after Effective Lifetime

Product status

Default status
unaffected

21.2R3 before 21.2R3-S8
affected

21.4R2 before 21.4R3-S6
affected

22.1 before 22.1R3-S5
affected

22.2 before 22.2R3-S3
affected

22.3 before 22.3R3-S2
affected

22.4 before 22.4R3-S1
affected

23.2 before 23.2R2
affected

23.4 before 23.4R2
affected

References

https://supportportal.juniper.net/JSA83012 vendor-advisory

cve.org CVE-2024-39550

nvd.nist.gov CVE-2024-39550

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2024-39550
© Copyright 2024 THREATINT. Made in Cyprus with +